CVE Database
/

CVE-2020-5132

Back to search

CVE-2020-5132

Published: Sep 30, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

VendorProductVersions

SonicWall

SMA100

affected
SMA100 10.2.0.2-20sv

SonicWall

SMA1000

affected
SMA1000 12.4.0-2223

SonicWall

SonicOS

affected
SonicOS 6.5.4.6-79n

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now