A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malicious request to the firewall. This vulnerability affected SonicOS Gen 6 version 6.5.4.7, 6.5.1.12, 6.0.5.3, SonicOSv 6.5.4.v and Gen 7 version 7.0.0.0.
Conclusion & alert: CVE-2020-5135 is rated Critical Active Threat (99.8/100): CVSS Critical severity, with high exploitation likelihood (EPSS 26.87%, 98th percentile).Core evidence: CISA KEV confirms active exploitation (added 2022-03-15) affecting SonicWall / SonicOS. a weakness (CWE-120) Unauthenticated remote administrative access may be possible. EPSS rose +1.38% over the last day, indicating growing attacker interest.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Required action: Apply updates per vendor instructions.
Exploit prediction scoring system (EPSS) score for CVE-2020-5135
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).