HomeSecuritySonicWall: The trap of “incomplete patching” that leaves the door open to attacks

SonicWall: The “incomplete patching” trap that leaves the door open to attacks

Many IT teams believe they “just updated the firmware” and their VPN is secure. But new reports show that on SonicWall Gen6 SSL-VPN appliances, attackers can bypass MFA when CVE-2024-12802 is not addressed with the necessary manual steps. The result? Attacks start with brute-force/credential stuffing and end up with “legit”-looking access in the logs, paving the way for ransomware tooling.

See also: Security Alarm for SonicWall SMA Devices

SonicWall

What happened in the attacks studied?

According to the analysis presented, responders encountered multiple intrusions between February and March, where the attacker:
– brute-forced VPN credentials,
– logged into a SonicWall SSL-VPN without being "cut off" by MFA,
– stayed inside for 30–60 minutes for recon and credential reuse testing,
– attempted to deploy a Cobalt Strike beacon and vulnerable driver (BYOVD) to potentially disable EDR. 

In at least one incident, access from a VPN to a domain-joined file server was achieved within about half an hour, while the attacker opened an RDP session using a shared local admin password. CVE-2024-12802 is related to “missing MFA enforcement” when using the UPN login format, allowing an attacker with valid credentials to authenticate without triggering the MFA requirement. The crucial point: SonicWall has warned that in Gen6, a firmware update alone is not enough, a manual change to the LDAP configuration is also required — otherwise, bypass is still possible.

See also: Hackers Target SonicWall Firewalls from 4,000+ IP Addresses

SonicWall: The “incomplete patching” trap that leaves the door open to attacks
  • For Gen7/Gen8, updating to newer firmware is reported to be sufficient to eliminate the risk.
  • For Gen6, update + manual remediation (LDAP reconfiguration) is required.
  • Additionally, it is noted that Gen6 SSL-VPN appliances have reached end-of-life on April 16th (and therefore, overall, the strategy should be migration to supported devices).

Based on the instructions provided, admins should complete the following:
1) Delete the existing LDAP configuration that uses userPrincipalName in the “Qualified login name”.
2) Remove locally cached/listed LDAP users.
3) Remove the SSL VPN “User Domain” (reverts to LocalDomain).
4) Reboot the firewall.
5) Recreate the LDAP configuration without userPrincipalName in the “Qualified login name”.
6) Take a new backup (so as not to restore to a vulnerable config). 

See also: Marquis sues SonicWall for breach that led to ransomware

SonicWall: The “incomplete patching” trap that leaves the door open to attacks

Many SMEs, accounting firms, engineering firms, schools/tutoring centers and organizations use SSL-VPN appliances for remote access. If you have SonicWall Gen6, the case shows that “update” is not enough: you need to check the config and hunt for suspicious entries. For companies that have external partners, shared local admin passwords and RDP to servers, the risk escalates — because an attacker can move laterally in less than an hour. 

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS