HomeSecuritySonicWall bug in 800K firewalls: Does the solution finally fix the problem?

SonicWall bug in 800K firewalls: Does the solution finally fix the problem?

New findings have emerged that shed light on a critical SonicWall bug that was revealed last year, which was initially thought to have been fixed.

In October of last year, a critical buffer overflow vulnerability, referenced as CVE-2020-5135, was discovered, affecting over 800,000 SonicWall VPNs.

When exploited, the vulnerability could allow unauthenticated remote attackers to execute arbitrary code on affected devices or cause Denial of Service (DoS) attacks.

As it now turns out, the vulnerability has not been properly patched. CVE-2021-20019 has been assigned to the flaw as a new vulnerability identifier.

See also: Ransomware group exploits SonicWall zero-day to compromise networks

SonicWall firewall bugs

SonicWall bug in 800K VPN firewalls has been partially fixed

In October of last year, BleepingComputer reported on a critical buffer overflow vulnerability in SonicWall VPN firewalls. The vulnerability, reported as CVE-2020-5135, existed in versions of SonicOS, which manage more than 800,000 active SonicWall devices.

Craig Young (of Tripwire's VERT team) and Nikita Abramov (Positive Technologies) were initially credited with discovering and reporting the vulnerability.

But, now, Tripwire has contacted BleepingComputer, claiming that the previous fix for the flaw was “unsuccessful.

The critical buffer overflow vulnerability allows an attacker to send a malicious HTTP request to the firewall to cause a Denial of Service (DoS) or execute arbitrary code.

After a series of emails between Tripwire researcher Craig Young and SonicWall, the vulnerability was eventually addressed as a problem and patched.

Also read: SonicWall releases additional update for SMA 100 vulnerability

But later, the researcher retested the proof-of-concept (PoC) exploit against SonicWall instances and concluded that the fix had "failed.".

The Tripwire researcher was surprised to notice, however, that in this case, his PoC exploit did not cause a system error – but a flood of binary data in the HTTP response:

SonicWall bug in 800K firewalls: Does the solution finally fix the problem?

This is where Young contacted SonicWall again. Young states that the binary data returned in HTTP responses could be memory addresses. After reporting this to SonicWall on October 6, 2020, the researcher made two more follow-ups in March 2021.

SonicWall today released advisories [1, 2] related to this vulnerability, with more information on the stable releases.

See also: SonicWall: Zero-day vulnerability exploited by hackers

Although most versions have a patch, platforms including NSsp 12K, SuperMassive 10k, and SuperMassive 9800 are awaiting the patch release.

Therefore, SonicWall customers are advised to monitor advisory pages for updates.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS