Nearly 800,000 SonicWall VPNs are vulnerable to a new critical vulnerability. This means that updates must be made immediately to keep users ' systems safe

The new vulnerability, codenamed CVE-2020-5135, was discovered by the Tripwire VERT security team . According to the researchers, it affects SonicOS , the operating system of SonicWall Network Security Appliance (NSA) devices .
SonicWall NSAs are used as firewalls and SSL VPN portals that filter, audit, and allow employees to access internal and private networks.
Tripwire researchers say that SonicOS contains a bug in a component that handles custom protocols.
This particular component is exposed on the WAN (public internet) interface, which means that any attacker can exploit it, as long as they know the device's IP address.
The worrying thing, according to Tripwire, is that exploiting the bug is extremely easy and can be done even by someone with no special knowledge of hacking. The simplest problem that can be created by exploiting the vulnerability is a denial of service attack or crashing a device. However, executing malicious code is also possible.
The security firm said it notified the SonicWall team, which released updates to fix the vulnerability on Monday.
On Wednesday, when he disclosed the CVE-2020-5135 bug, Tripwire VERT security researcher Craig Young said the company had identified 795,357 SonicWall VPNs that were connected to the internet and were likely vulnerable to the vulnerability.

Researchers consider the vulnerability critical and have rated it 9.4/10 (in terms of severity). Users should update their SonicWall VPNs immediately, as proof-of-concept code has been published, so hackers may have already begun exploiting it. Exploiting the vulnerability does not require an attacker to have valid credentials, as the error occurs before any authentication operation.
According to ZDNet, this is the second largest vulnerability discovered in SonicWall products this year. Last winter, the vulnerability CVE-2019-7481 was discovered.
Researchers from Tenable and Microsoft have shared this week Shodan to identify SonicWall VPNs and fix them.
