CVE-2023-39277: SonicWall SonicOS

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

SonicOS post-authentication stack-based buffer overflow vulnerability in the sonicflow.csv and appflowsessions.csv URL endpoints leads to a firewall crash.

Affected products

  • SonicWall SonicOS: before 7.0.1-5145 (fixed in 7.0.1-5145); before 6.5.4.4-44v-21-2340 (fixed in 6.5.4.4-44v-21-2340); before 6.5.4.13-105n (fixed in 6.5.4.13-105n)

Published 2023-10-17. Last modified 2026-06-17.