SonicWall has released a second firmware update for a zero-day vulnerability SMA-100 that is known to be used in attacks and warns that installation should be immediate.
Last month, SonicWall revealed that its internal systems were attacked after exploiting a zero-day vulnerability in its SMA-100 remote access appliances. A week later, cybersecurity firm NCC Group discovered the zero-day vulnerability used in that attack.
On February 3, Sonicwall released a patch for the zero-day vulnerability and strongly recommended that all users install it.

Additional safeguards added to the firmware
Yesterday, SonicWall announced new firmware updates for SMA-100 series appliances that provide additional safeguards discovered since their last update.
“Following the February 3 firmware update described below, SonicWall announces the availability of new firmware versions for both codecs (10.x and 9.x) on the products , which consists of the physical SMA 200, 210, 400, 410 appliances and the virtual SMA 500v appliance.”
“SonicWall has conducted additional reviews to further strengthen the code for the SMA 100 product line,” SonicWall announced.
Although SonicWall does not describe what security fixes were added in this update, it emphasizes that all users should “IMMEDIATELY” upgrade their devices.
The changes in this new update are:
The new SMA 10.2 firmware includes:
- Code-hardening fixes identified during internal code review
- Collection of fixes for client issues not included in the February 3rd patch
- General performance improvements
- Additional fixes in the patch released on February 3rd in the SMA 100 series
The new firmware 9.0 includes:
- Code-hardening fixes identified during internal code review
These updates apply to the SMA 200, SMA 210, SMA 400, SMA 410 physical appliances and the SMA 500v virtual appliances (Azure, AWS, ESXi, HyperV).
Owners can find instructions on how to apply the updates in SonicWall's advisory
Information source: bleepingcomputer.com
