Integer-based buffer overflow vulnerability allows DoS and arbitrary code execution

CVE-2024-22396
Currently unrated 🤨

Key Information

Vendor
Sonicwall
Status
Sonicos
Vendor
CVE Published:
14 March 2024

Summary

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

Affected Version(s)

SonicOS = 7.0.1-5145 and earlier versions

SonicOS = 7.1.1-7047 and earlier versions

SonicOS = 6.5.4.13-105n and earlier versions

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.