CVE-2020-5132 - CVE House
Back to Database
Status published Medium CVE-2020-5132

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads...

Vulnerability Description

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5132

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SMA100, SMA1000, SonicOS
Vulnerable Versions:
SMA100 10.2.0.2-20sv, SMA1000 12.4.0-2223, SonicOS 6.5.4.6-79n

Timeline

Official Publish: September 30th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)