ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

SonicWall: Attacks Linked to Legacy Bug and Password Use

criticalRansomwareimportance 60CVE-2024-40766

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40766
Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls)

CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile).

Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents.

9.818% KEV ransomware
  • SonicWall SonicOS (Gen 5 firewalls) Gen 5 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 6 firewalls) Gen 6 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 7 firewalls) SonicOS 7.0.1-5035 and older
mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances)
Full article349 words · extracted from infosecurity-magazine.com · click to collapse

A leading security vendor has dismissed claims of a zero-day vulnerability in its products, stating that a surge in ransomware attacks against customers is due to poor password management.

As reported by Infosecurity earlier this week, researchers from multiple threat detection providers observed an increase in Akira ransomware intrusions against SonicWall customers in late July.

“In some instances, fully patched SonicWall devices were affected following credential rotation. Despite TOTP [time-based one-time password] MFA being enabled, accounts were still compromised in some instances,” Arctic Wolf claimed.

However, in an updated statement today, SonicWall posited another cause of the successful attacks on its Gen 7 and newer firewalls with SSLVPN enabled.

“We now have high confidence that the recent SSLVPN activity is not connected to a zero-day vulnerability. Instead, there is a significant correlation with threat activity related to CVE-2024-40766, which was previously disclosed and documented in our public advisory SNWLID-2024-0015,” it explained.

“We are currently investigating less than 40 incidents related to this cyber activity. Many of the incidents relate to migrations from Gen 6 to Gen 7 firewalls, where local user passwords were carried over during the migration and not reset. Resetting passwords was a critical step outlined in the original advisory.”

Read more on threats to SonicWall customers: Critical SonicWall SSLVPN Bug Exploited by Ransomware Actors

Updated Advice for Customers

The security vendor strongly urged all customers who imported configuration settings from Gen 6 to newer firewalls to update to SonicOS 7.3, which has built-in protection against brute-force password and multi-factor authentication (MFA) attacks.

“Without these additional protections, password and MFA brute-force attacks are more feasible,” it warned.

SonicWall also urged customers to reset all local user account passwords for any accounts with SSLVPN access, especially if they were carried over during migration from Gen 6 to Gen 7.

It added that previous advice still applies, that is:

  • Enable Botnet Protection and Geo-IP Filtering
  • Remove unused or inactive user accounts
  • Enforce MFA and strong password policies

The security vendor also thanked the research community – including Arctic Wolf, Google Mandiant, Huntress and Field Effect – for their vigilance.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/sonicwall-attacks-legacy-bug/