Ransomware Attacks Targeting Unpatched EOL SonicWall SMA 100 VPN Appliances
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-7481 | Unauthenticated SQL Injection in SonicWall SMA100 Appliances SonicWall SMA100 secure-access appliances contain a SQL injection flaw (CWE-89) that requires no authentication to exploit. A remote attacker sends crafted input to the vulnerable appliance, most plausibly through its internet-facing web/remote-access interface, and gains read-only access to resources they are not authorized to see. An attacker is therefore limited to reading unauthorized data, but the flaw provides unauthenticated access to a network edge device and a basis for further reconnaissance. Any organization running a SonicWall SMA100 appliance — typically deployed as an internet-exposed SSL-VPN/remote-access gateway — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use noted, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile). Do: Apply firmware updates to SMA100 appliances per SonicWall's instructions, as CISA's required action states and no fixed version is given in this data. Because CISA notes known ransomware use, prioritize patching any internet-exposed SMA device, review appliance and firewall logs for unexpected unauthenticated access, and as an interim mitigation restrict exposure of the appliance's web interface to trusted source addresses. | 7.5 | 100% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed SMA100/SSL-VPN appliances | |
| CVE-2021-20016 | Unauthenticated SQL Injection in SonicWall SMA100 SSL VPN CVE-2021-20016 is an unauthenticated SQL injection flaw (CWE-89) in the SonicWall SSL-VPN service on SMA 100 appliances. It is triggered remotely by malicious, unauthenticated requests to the appliance's web interface, allowing SQL injection against the backend database. Successful exploitation gives the attacker credential access — harvesting valid user credentials that can then be used to log into the SSL-VPN and pivot into the victim network. Any organization running an internet-facing SonicWall SSLVPN SMA100 appliance is affected, and CISA notes known ransomware use of this flaw. It was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 40% EPSS probability of exploitation within 30 days (99th percentile), so it should be treated as actively exploited even though no public proof-of-concept is known. Do: Apply the SonicWall firmware update per vendor instructions, as required by the CISA KEV listing. Because ransomware operators are known to exploit this flaw, review SMA100 authentication and admin logs for unfamiliar logins, rotate exposed credentials, and restrict the appliance to trusted source IPs until it is patched. CVSS has not yet been scored, but the 40% EPSS (99th percentile) and KEV status warrant immediate patching of all internet-exposed units. | 9.8 | 40% | KEV ransomware |
| large≈ tens of thousands of internet-exposed SMA100 appliances (public scan counts of SonicWall SSL-VPN endpoints) |
Full article353 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 15, 2021
Networking equipment maker SonicWall is alerting customers of an "imminent" ransomware campaign targeting its Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) products running unpatched and end-of-life 8.x firmware.
The warning comes more than a month after reports emerged that remote access vulnerabilities in SonicWall SRA 4600 VPN appliances (CVE-2019-7481) are being exploited as an initial access vector for ransomware attacks to breach corporate networks worldwide.
"SonicWall has been made aware of threat actors actively targeting Secure Mobile Access (SMA) 100 series and Secure Remote Access (SRA) products running unpatched and end-of-life (EOL) 8.x firmware in an imminent ransomware campaign using stolen credentials," the company said. "The exploitation targets a known vulnerability that has been patched in newer versions of firmware."
SMA 1000 series products are not affected by the flaw, SonicWall noted, urging businesses to take immediate action by either updating their firmware wherever applicable, turning on multi-factor authentication, or disconnecting the appliances that are past end-of-life status and cannot be updated to 9.x firmware.
"The affected end-of-life devices with 8.x firmware are past temporary mitigations. Continued use of this firmware or end-of-life devices is an active security risk," the company cautioned. As additional mitigation, SonicWall is also recommending customers reset all passwords associated with the SMA or SRA device, as well as any other devices or systems that may be using the same credentials.
The development also marks the fourth time SonicWall devices have emerged as a lucrative attack vector, with threat actors exploiting previously undisclosed flaws to drop malware and dig deeper into the targeted networks, making it the latest issue the company has grappled with in recent months.
In April, FireEye Mandiant disclosed that a hacking group tracked as UNC2447 was using a then-zero-day flaw in SonicWall VPN appliances (CVE-2021-20016) prior to it being patched by the company to deploy a new strain of ransomware called FIVEHANDS on the networks of North American and European entities.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/07/ransomware-attacks-targeting-unpatched.html