sonicwall sonicos CVE-2020-5142 vulnerability in SonicWall Products
Published on October 12, 2020

A stored cross-site scripting (XSS) vulnerability exists in the SonicOS SSLVPN web interface. A remote unauthenticated attacker is able to store and potentially execute arbitrary JavaScript code in the firewall SSLVPN portal. This vulnerability affected SonicOS Gen 5 version 5.9.1.7, 5.9.1.13, Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version SonicOS 7.0.0.0.

NVD

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2020-5142 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2020-5142

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-5142 are published in these products:

 
 

Affected Versions

SonicWall SonicOS:

Exploit Probability

EPSS
0.14%
Percentile
33.24%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.