SonicWall has issued an urgent notice urging all customers to perform a Forced Credential Reset after security researchers discovered that SonicWall's MySonicWall configuration backup files were accidentally exposed to public storage.
See also: SonicWall: Brute force attacks hit firewall configuration backups

The sensitive files contained encrypted passwords, pre-shared keys, and TLS certificates used by SonicOS devices, potentially allowing malicious users to decrypt and exploit the credentials to gain unauthorized network access.
The SonicWall Knowledge Base describes three critical phases: Containment, Remediation, and Monitoring, to mitigate risk and restore secure operation.
To immediately reduce exposure, SonicWall recommends disabling or restricting all WAN management services before proceeding with password resets. Administrators should go to Network → System → Interfaces, edit each WAN interface, and disable HTTP/HTTPS & SSH Management.
Similarly, SSL VPN and IPsec VPN services should be disabled via Network → SSL VPN → Server Settings and Network → IPsec VPN → Rules and Settings, respectively. SNMP v3 access should be disabled under Device → Settings → SNMP to prevent unauthorized SNMP GET/SET commands from exposing machine IDs or community strings. Restricting inbound NAT/Access rules to known/trusted IP addresses further prevents attackers from reconnecting after credential changes.
See also: ACSC warns of SonicWall access vulnerability

SonicOS 6.5.5.1 and 7.3.0 feature a dynamic enforcement option that locks user accounts until a new password is set, ensuring that the restriction remains effective even if WAN restrictions cannot be fully enforced. Key actions include resetting passwords for all Local Users and re-writing TOTP bindings. Administrators should update login account passwords on LDAP, RADIUS , and TACACS+, rotating shared secrets with SHA-256 values.
All pre-shared IPsec VPN keys—used for site-to-site and GroupVPN tunnels—require replacement with new AES-256 encrypted secrets, with corresponding updates to remote gateways. WAN interface credentials for L2TP/PPPoE/PPTP and cellular WWAN must be renewed in coordination with ISPs. Dynamic DNS, Clearpass NAC, and email logging automation accounts must have their passwords reset to avoid delivery failures.
Finally, update the encryption keys in the IPSec Management feature of the Global Management System (GMS) under Device → Settings → Management. After recovery, re-enable the services in stages, verifying each with a successful login test and SSH key rotation. Customers relying on automated workflows are reminded to update the scripts that reference the old credentials.
Continuous monitoring of the system and logs is essential. Administrators should review Logs → System Logs and Audit Logs, filtering for repeated authentication failures or anomalies in configuration changes. Export logs to CSV for detailed analysis and leverage SIEM integrations using Syslog over TLS 1.2 to ensure secure forwarding.
See also: SonicWall: Disable SSL VPN due to ransomware

By following these steps, you will protect SonicWall environments from exploitation of exposed configuration backups and strengthen the integrity of network defense perimeters.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
