Patch these SonicWall zero-days now, customers warned

Zero-day attack
(Image credit: Shutterstock.com)

Cybersecurity solutions provider SonicWall has asked businesses using its Email Security (ES) products to upgrade to the latest version in order to mitigate a set of serious zero-day vulnerabilities.

Researchers at security firm Mandiant Managed Defense were first to identify the three vulnerabilities, which were being actively exploited in the wild. In a blog post, the researchers described the attack made possible by the vulnerabilities.

They note that the flaws were chained and executed in conjunction by the threat actors in order to gain administrative access and code execution permissions on a SonicWall ES device.

TechRadar needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

The good news, though, is that all three vulnerabilities have now been patched.

“It is imperative that organizations using SonicWall Email Security hardware appliances, virtual appliances or software installation on Microsoft Windows Server immediately upgrade to the respective SonicWall Email Security version,” said SonicWall.

Complex attack

One of the vulnerabilities, tracked as CVE-2021-20021, has a very high Common Vulnerability Scoring System (CVSS) rating of 9.4/10, as it can be exploited to create an administrative account by sending a crafted HTTP request to the remote host.

Mandiant researchers became aware of the vulnerabilities while investigating a post-exploitation backdoor in a customer’s SonicWall Email Security instance running atop a Windows Server 2012 installation.

They note that the attackers had intimate knowledge of the SonicWall application and used a combination of all the three exploits interchangeably to not just install a backdoor, but also access files and emails, and traverse the victim organization’s network.

SonicWall, for its part, has provided step-by-step instructions to enable its customers to apply the security update in order to mitigate the vulnerabilities.

Update:

A SonicWall spokesperson has since provided TechRadar Pro with the following statement:

"SonicWall routinely collaborates with third-party researchers and forensic analysis firms to ensure that our products meet or exceed security best practices. Through the course of this process, SonicWall was made aware of and verified certain zero-day vulnerabilities to its hosted and on-premises email security products. SonicWall designed, tested and published patches to correct the issues and communicated these mitigations to customers and partners."
 
"SonicWall strongly encourages customers — as well as organizations worldwide — to maintain diligence in patch management to strengthen the community’s collective security posture."

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Representational image depecting cybersecurity protection
Hackers are breaking SonicWall products to target business networks
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
Flag of the People&#039;s Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall VPN flaw could allow hackers to hijack your sessions, so patch now
Latest in Pro
cybersecurity
What's the right type of web hosting for me?
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
construction
Building in the digital age: why construction’s future depends on scaling jobsite intelligence
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras