HomeSecuritySonicWall: Thousands of firewalls vulnerable to DoS and RCE attacks

SonicWall: Thousands of firewalls vulnerable to DoS and RCE attacks

Security researchers have identified over 178,000 SonicWall next-generation firewalls (NGFW) that have their management interface exposed to the internet, making them vulnerable to denial-of-service (DoS) . and remote code execution (RCE) attacks

SonicWall firewalls

Specifically, the devices are affected by two DoS vulnerabilities, CVE-2022-22274 and CVE-2023-0656. The former also allows attackers to gain remote code execution capabilities.

According to Jon Williams, Senior Security Engineer at Bishop Fox, SonicWall firewalls with exposed management interfaces are vulnerable to one or both of the above two vulnerabilities.

Both bugs are caused by the reuse of the same vulnerable code pattern, but their exploitation occurs on different HTTP URI paths, according to the researchers.

See also: Juniper: Critical vulnerability in firewalls and switches

“Our initial investigation confirmed the vendor’s claim that there was no exploit available; however, once we identified the vulnerable code, we discovered that it was the same issue that was announced a year later as CVE-2023-0656,” Williams said.

“We found that CVE-2022-22274 was caused by the same vulnerable code pattern in a different place and the exploit worked on three additional URI paths“.

Researchers say that even if attackers are unable to execute code on a vulnerable SonicWall device, they can exploit the vulnerabilities to put it into maintenance mode, requiring intervention from administrators to start operating normally again.

Therefore, even if remote code execution is not assured, attackers could exploit these vulnerabilities to disable edge firewalls and the VPN they provide to corporate networks.

See also: NoName: DDoS attacks against Ukrainian government websites

SonicWall: Thousands of firewalls vulnerable to DoS and RCE attacks

More than 500,000 SonicWall firewalls are currently exposed online, with more than 328,000 located in the United States.

SonicWall security experts say they have not found evidence that the vulnerabilities have been used in attacks, but there is at least one proof-of-concept (PoC) exploit online for CVE-2022-22274.

Administrators are urged to ensure that the management interface of SonicWall NGFW appliances is not exposed to the internet and to apply the latest firmware versions to stay protected.

See also: Microsoft SharePoint: Critical vulnerability used for attacks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, using strong passwords and monitoring system logs are recommended as general security measures. Using strong, unique passwords is crucial. This can help protect against attacks that exploit weak or repetitive passwords.

Monitoring and analyzing system logscan help detect attacks. This may include examining traffic patterns or looking for unusual behavior.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS