Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

10/23/2020
05:05 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Positive Technologies Helps Fix 11 Vulnerabilities in Popular SonicWall Firewall Appliances

Potential threats included disconnection of remote employees or branches and possible attacker penetration into corporate networks.

Framingham, MA (October 22, 2020) – SonicWall patched vulnerabilities in SonicOS for firewall appliances discovered by Positive Technologies expert Nikita Abramov. According to IDC, SonicWall ranks fifth among manufacturers of gateway security appliance solutions worldwide.

The most serious vulnerability, CVE-2020-5135, found by Nikita Abramov at Positive Technologies and Craig Young at Tripwire, is of critical severity (CVSS v3 score 9.4). This buffer overflow vulnerability in SonicOS allows remote attackers to cause denial of service (DoS) and potentially execute arbitrary code.

Nikita Abramov researcher at Positive Technologies explained: “The tested solution uses a SSL-VPN remote access service on firewalls, and users can be disconnected from internal networks and their workstations in case of a DoS attack. If attackers manage to execute arbitrary code, they may be able to develop an attack and penetrate the company's internal networks.”

“This is best practice for vendor-researcher collaboration in the modern era,” said SonicWall's Aria Eslambolchizadeh, Head of Quality Engineering. “These types of open and transparent relationships protect the integrity of the online landscape, and ensure better protection from advanced threats and emerging vulnerabilities before they impact end users, as was the case here.”

CVE-2020-5135 affects SonicOS 6.5.4.7-79n, SonicOS 6.5.1.11-4n, SonicOS 6.0.5.3-93o and SonicOSv 6.5.4.4-44v-21-794 (including older versions). To fix CVE-2020-5135, users need to upgrade to the following firmware versions (depending on their product): SonicOS 6.5.4.7-83n, SonicOS 6.5.1.12-1n, SonicOS 6.0.5.3-94o or SonicOS 6.5.4.v-21s-987. 

Another vulnerability, CVE-2020-5133, received a CVSS v3 score of 8.2. This vulnerability allows a remote unauthenticated attacker to cause denial of service attacks due to buffer overflow, which leads to a firewall crash.

Failures in SonicOS can also be caused by exploitation of vulnerabilities CVE-2020-5137CVE-2020-5138CVE-2020-5139, and CVE-2020-5140 (all of them have a CVSS v3 score of 7.5 and can be exploited by remote unauthenticated attackers), and vulnerabilities CVE-2020-5134 and CVE-2020-5136 (CVSS v3 score 6.5, exploitation requires authentication).

In addition, a remote unauthenticated attacker can bruteforce Virtual Assist ticket ID in the SSL-VPN service (vulnerability CVE-2020-5141, CVSS v3 score 6.5). A cross-site scripting (XSS) vulnerability CVE-2020-5142 (CVSS v3 score 6.5) allows a remote unauthenticated attacker to potentially execute arbitrary JavaScript code in the firewall SSL-VPN portal. Finally, a SonicOS SSL-VPN login page could allow a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses (vulnerability CVE-2020-5143, CVSS v3 score 5.3). 

To migitate the vulnerabilities, follow the recommendations on the vendor's official website:  https://www.sonicwall.com/support/product-notification/sonicwall-dos-xss-vulnerabilities/201015132843063/

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Zero Trust doesn't have to break your budget!
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32243
PUBLISHED: 2021-06-16
FOGProject v1.5.9 is affected by a File Upload RCE (Authenticated).
CVE-2021-32244
PUBLISHED: 2021-06-16
Cross Site Scripting (XSS) in Moodle 3.10.3 allows remote attackers to execute arbitrary web script or HTML via the "Description" field.
CVE-2021-32245
PUBLISHED: 2021-06-16
In PageKit v1.0.18, a user can upload SVG files in the file upload portion of the CMS. These SVG files can contain malicious scripts. This file will be uploaded to the system and it will not be stripped or filtered. The user can create a link on the website pointing to "/storage/exp.svg" t...
CVE-2021-34201
PUBLISHED: 2021-06-16
D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process crashes or changes.
CVE-2021-34203
PUBLISHED: 2021-06-16
D-Link DIR-2640-US 1.01B04 is vulnerable to Incorrect Access Control. Router ac2600 (dir-2640-us), when setting PPPoE, will start quagga process in the way of whole network monitoring, and this function uses the original default password and port. An attacker can easily use telnet to log in, modify ...