Integer-based buffer overflow vulnerability allows DoS and arbitrary code execution
CVE-2024-22396

Currently unrated

Key Information:

Vendor
Sonicwall
Status
Vendor
CVE Published:
14 March 2024

Summary

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

Affected Version(s)

SonicOS Gen6 7.0.1-5145 and earlier versions

SonicOS Gen6 7.1.1-7047 and earlier versions

SonicOS Gen6 6.5.4.13-105n and earlier versions

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.