SonicWall VPN Vulnerability Calls for Immediate Patch

Hundreds of thousands of VPNs all over the world are in need of patching after a critical security bug has been discovered. The flaw, tracked as CVE-2020-5135, is a stack-based buffer overflow in the SonicWall Network Security Appliance (NSA). It exists in the HTTP/HTTPS service that is used for SSL VPN remote access.

Since VPN bugs can make entry points into sensitive networks easily visible, these bugs are known to be extremely dangerous. Even after breaching a VPN, attackers have the ability to map out a target network for some time before making any ransomware demands. With this particular vulnerability, a username and password doesn’t even have to be known in order to exploit the VPN portal.

Below are the SonicWall VPN devices impacted by CVE-2020-5135:

  • SonicOS 6.5.4.7-79n and earlier
  • SonicOS 6.5.1.11-4n and earlier
  • SonicOS 6.0.5.3-93o and earlier
  • SonicOSv 6.5.4.4-44v-21-794 and earlier
  • SonicOS 7.0.0.0-1

To resolve the issue, SonicWall issued updates and suggests to temporarily disconnect SSL VPN portals before applying the patch.

Below are the versions available to upgrade:

  • SonicOS 6.5.4.7-83n
  • SonicOS 6.5.1.12-1n
  • SonicOS 6.0.5.3-94o
  • SonicOS 6.5.4.v-21s-987
  • Gen 7 7.0.0.0-2 and onwards

Due to the large number of people still working remotely, VPNs are being heavily relied on. Once they are exploited by flaws like this, it becomes very concerning because your security could be compromised. Questions? Call CATS Technology Solutions Group (732-204-7100) and a certified IT specialist will take care of you!

About CATS Technology

CATS Technology is a complete technology solutions provider, dedicated to providing solutions that will streamline operations, enhance productivity and drive innovation for businesses of all sizes. Our professionally trained and certified IT experts empower our clients to leverage the full potential of their IT investments to stay ahead of today’s rapidly evolving digital landscape. 

Meet Cyberman

Our Services

Client Portal

Have you visited CATS Technology’s new Client Portal yet? It has been designed to provide everything you’ll need, all in one place. 

  • Submit Tickets
  • Track Ticket Status
  • Edit Ticket Content 
  • View and Pay invoices

Related Posts

Why Hackers Love the New Year: Cyber Security Risks in 2026

The New Year feels like a fresh start for businessess, but for cybercriminals, it’s the perfect opportunity. From distracted employees to system changes and weak passwords, early 2026 creates the ideal conditions for cyberattacks. Learn why businesses are more vulnerable at the start of the year, and how to stay protected.

Read More
cybersecurity training

You Can’t Patch People: The Real Challenge in Cybersecurity Training

No matter how advanced our security tools become, there is one vulnerability that can never be fixed with a patch or an update, and that’s human behavior. Organizations can deploy the latest firewalls, endpoint protection, and threat detection systems, yet a single moment of human error can still open the door to an attacker. This isn’t a failure of technology, it shows that cybersecurity comes down to human decisions, which is why staying updated and alert to new threats is so essential.

Read More