Security researchers discovered six serious security issues affecting various Dell Sonicwall products, one of which is a hidden account with “easy» credentials.
The security company Digital Defense, Inc. (DDI), based in the USA, found the issues and reported the problems to Dell, which yesterday released patches to address all the reported bugs.
DDI says that the issues located in the Dell SonicWALL Global Management System (GMS), a central management console, which reports and monitors SonicWALL devices such as the company's VPNs and firewalls.
According to some tips that have been released, the DDI team is revealing details about a hidden default account that uses a very easy password.
“This hidden account can be used to add non-administrative users via the CLI client that can be downloaded from the console interface of the GMS web application. The non-administrative user can then log into the web interfaces and change the administrator's password, changing its privileges to those of the administrator. This will give the intruder full control of the GMS interface and all connected SonicWALL devices.“
Additionally, the research team discovered two unauthenticated root command injections that lead to RCE (remote code execution) with root privileges on Dell equipment.
Adding these two unauthenticated XML External Entity Injection (XXE) flaws and another issue that allowed changes to the settings without network authentication via the GMC service, we end up having a very good reason to apply the Dell patches, even if you are running the said equipment on your network.
Dell has acknowledged all reports and patches have been issued for all affected customers using the GMS platform.
Dell is just the latest networking equipment vendor to be found with a backdoor in its devices, following similar incidents with Fortinet and Juniper.

