HomeSecurityA bug was detected in the SonicWall firewall cloud system

A bug has been detected in the SonicWall firewall cloud system

A bug was recently discovered in a cloud system used to manage SonicWall firewalls. The bug could allow hackers to break into thousands of corporate networks.

Corporate firewalls and virtual private network devices are vital systems for protecting corporate networks from hackers and various cyber attacks .Hackers are known to look for flaws in critical network tools to penetrate corporate networks with the aim of stealing data or installing malware.

SonicWall bug

Vangelis Stykas, a researcher at security firm Pen Test Partners, found the new bug in SonicWall's Global Management System (GMS), a web application that allows IT departments to remotely configure SonicWall devices on the network.

However, the bug, if exploited, meant that any existing user with access to SonicWall's GMS could create a user account with access to any other company's without permission.

From there, the newly created account could remotely manage that company's SonicWall tools.

In a blog post shared with TechCrunch, Stykas said there were two barriers to entry. First, a would-be attacker would need an existing SonicWall GMS user account. The easiest way — and what Stykas did to independently verify the flaw — was to purchase a SonicWall appliance.

The second issue was that the would-be attacker would have to guess a unique seven-digit number associated with another company 's network . But Stykas said that number was sequential and the hacker could easily guess it.

If the hacker managed to break into a company's network, they could deliver ransomware directly to the victims' internal systems – a very popular tactic among hackers carrying out financially motivated attacks.

SonicWall confirmed that the bug has now been fixed. But Stykas criticized the company for taking more than two weeks to fix the vulnerability, which the company described as "insignificant.".

"Even car alarm vendors have fixed similar problems within three days of our report," the researcher said.

A SonicWall spokesperson defended the company's decision, saying it had to subject the fix to a "thorough" quality check before releasing it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS