SonicWall networking kit abused in network compromise attacks
Active zero-day exploit has been identified, but patch is available now
UPDATE: SonicWall has now released what it calls "a critical firmware update" to patch the zero-day vulnerability detected on SMA 100 series 10.x code.
"All SonicWall customers with active SMA 100 series devices running 10.x code should immediately apply the patch on physical and virtual appliances," the company said in a statement. "The patch also contains additional code to strengthen the device."
"As previously stated, SonicWall firewalls and SMA 1000 series appliances, as well as all respective VPN clients, are unaffected and remain safe to use. No action for these products is required."
Security firm the NCC Group believes that it has identified an active exploit involving a zero-day SonicWall vulnerability that was disclosed last week. The company has not revealed exact details regarding the exploit as that might enable further attacks to be launched.
“Per the SonicWall advisory… we've identified and demonstrated exploitability of a possible candidate for the vulnerability described and sent details to SonicWall - we've also seen indication of indiscriminate use of an exploit in the wild - check logs,” NCC explained in a tweet.
SonicWall has not confirmed whether the exploit discovered by NCC researchers involves one of the vulnerabilities disclosed last week. Until more information is revealed, NCC has advised that owners of the vulnerable SonicWall devices cited in the firm’s recent security advisory should restrict the IP addresses that are allowed to access the management interface to only those associated with authorized personnel.
- We've highlighted the best antivirus solutions around
- Check out our roundup of the best firewalls
- We've also assembled a list of the best endpoint protection tools
Unconfirmed exploits
SonicWall recently warned customers that a zero-day vulnerability had been found affecting several of its VPN products. Following further investigation, however, the number of affected devices was significantly reduced.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Nevertheless, SonicWall admitted to the unconfirmed presence of a zero-day vulnerability affecting its SMA 100 Series – a range of networking devices used to provide access to internal networks for remote employees – something that has become increasingly needed with COVID-19 restrictions still in place for many businesses.
SonicWall is continuing to investigate potential vulnerabilities and reminded users of the importance of installing the latest security updates in order to guarantee protection against cybersecurity threats. The firm added that many of the proof of concept exploits being shared are not possible if patches released in 2015 are installed.
- Also, here's our list of the best routers for your business
Via ZDNet
Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services. After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things.