ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical flaw in SonicWall's firewalls patched, update quickly! (CVE-2020-5135)

criticalVulnerability exploited in the wildimportance 60CVE-2020-5135

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-5135
Buffer Overflow in SonicWall SonicOS Enables DoS and Potential RCE on Firewalls

CVE-2020-5135 is a buffer overflow vulnerability (CWE-120) in SonicWall's SonicOS firewall operating system. A remote attacker can trigger the flaw by sending a maliciously crafted request to a firewall running SonicOS, which can crash network services and cause a Denial of Service, with potential for arbitrary code execution. Because SonicOS runs on SonicWall perimeter firewalls and remote-access gateways, successful code execution would give an attacker a foothold at the network edge, a high-value position for both DoS and follow-on compromise. Any organization operating a SonicWall firewall running SonicOS is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, and EPSS estimates a 26.9% probability of exploitation within 30 days (98th percentile), indicating active and elevated exploitation risk even though no public PoC is known.

Do: Apply updated SonicOS firmware per SonicWall's instructions, as required by the CISA KEV listing, and confirm against SonicWall's advisory which firmware versions fix CVE-2020-5135 for your appliance. Until patched, restrict firewall management and remote-access (SSL-VPN) interfaces to trusted networks rather than the open internet. Given known ransomware use, hunt for signs of exploitation such as firewall crashes/reboots and anomalous outbound or lateral activity.

9.827% KEV ransomware
  • SonicWall SonicOS
mass≈ hundreds of thousands of internet-exposed SonicWall firewalls/remote-access endpoints
Full article496 words · extracted from helpnetsecurity.com · click to collapse

Earlier this week SonicWall patched 11 vulnerabilities affecting its Network Security Appliance (NSA). Among those is CVE-2020-5135, a critical stack-based buffer overflow vulnerability in the appliances’ VPN Portal that could be exploited to cause denial of service and possibly remote code execution.

CVE-2020-5135

About CVE-2020-5135

The SonicWall NSAs are next-generation firewall appliances, with a sandbox, an intrusion prevention system, SSL/TLS decryption and inspection capabilities, network-based malware protection, and VPN capabilities.

CVE-2020-5135 was discovered by Nikita Abramov of Positive Technologies and Craig Young of Tripwire’s Vulnerability and Exposures Research Team (VERT), and has been confirmed to affect:

  • SonicOS 6.5.4.7-79n and earlier
  • SonicOS 6.5.1.11-4n and earlier
  • SonicOS 6.0.5.3-93o and earlier
  • SonicOSv 6.5.4.4-44v-21-794 and earlier
  • SonicOS 7.0.0.0-1

“The flaw can be triggered by an unauthenticated HTTP request involving a custom protocol handler. The vulnerability exists within the HTTP/HTTPS service used for product management as well as SSL VPN remote access,” Tripwire VERT explained.

“This flaw exists pre-authentication and within a component (SSLVPN) which is typically exposed to the public Internet.”

By using Shodan, both Tripwire and Tenable researchers discovered nearly 800,000 SonicWall NSA devices with the affected HTTP server banner exposed on the internet. Though, as the latter noted, it is impossible to determine the actual number of vulnerable devices because their respective versions could not be determined (i.e., some may already have been patched).

A persistent DoS condition is apparently easy for attackers to achieve, as it requires no prior authentication and can be triggered by sending a specially crafted request to the vulnerable service/SSL VPN portal.

VERT says that a code execution exploit is “likely feasible,” though it’s a bit more difficult to pull off.

Mitigation and remediation

There is currently no evidence that the flaw is being actively exploited nor is there public PoC exploitation code available, so admins have a window of opportunity to upgrade affected devices.

Aside from implementing the offered update, they can alternatively disconnect the SSL VPN portal from the internet, though this action does not mitigate the risk of exploitation of some of the other flaws fixed by the latest updates.

Implementing the security updates is, therefore, the preferred step, especially because vulnerabilities in SSL VPN solutions are often targeted by cybercriminals and threat actors.

UPDATE (October 18, 2020, 2:00 a.m. PT):

“SonicWall was contacted by a third-party research team regarding issues related to SonicWall next-generation NSv virtual firewall models (6.5.4v) that could potentially result in Denial-of-Service (DoS) attacks and/or cross-site scripting (XSS) vulnerabilities. Immediately upon discovery, SonicWall researchers conducted extensive testing and code review to confirm the third-party research. This analysis lead to the discovery of 11 unique vulnerabilities requiring Common Vulnerabilities and Exposures (CVE) listings based on the Common Vulnerability Scoring System (CVSS),” a SonicWall spokesperson told Help Net Security.

“The PSIRT team worked to duplicate the issues and develop, test and release patches for the affected products. At this time, SonicWall is not aware of a vulnerability that has been exploited or that any customer has been impacted.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/10/16/cve-2020-5135/