ZeroHour
Security Affairspublished ()ingested @securityaffairs

SonicWall strongly urges customers to apply patches to SMA 100 devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-20038
Unauthenticated Stack Buffer Overflow in SonicWall SMA 100 Appliances

SonicWall SMA 100 series secure remote-access appliances contain an unauthenticated stack-based buffer overflow (CWE-121) in the appliance's network-facing interface, triggered by crafted requests sent to the device without any credentials. A remote attacker who triggers the overflow can execute arbitrary code on the appliance with the privileges of the affected service, gaining a foothold on an internet-facing VPN gateway that typically sits at the network edge. Any organization running an SMA 100 series appliance is affected, and because these appliances provide remote access to corporate networks, compromise can expose entire internal environments. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-01-28 with known ransomware use, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in the provided data, but the KEV listing and EPSS score indicate active attacker interest.

Do: Upgrade SMA 100 series appliances to firmware 10.0.7.2 or later per SonicWall's instructions, as required by the CISA KEV listing. Until patched, restrict internet exposure of the SMA portal and management interface to trusted sources where feasible. Because ransomware operators are known to exploit this flaw, review appliance logs for signs of compromise and monitor for unexpected account creation or traffic after patching.

9.8100% KEV ransomware PoC ×2
  • SonicWall SMA 100 Appliances Per SonicWall's advisory, SMA 100 series firmware 10.0.7.1 and earlier (fixed in 10.0.7.2 and later); the CISA record does not specify version ranges, so admini
largetens of thousands of internet-exposed SMA 100 appliances (order of magnitude ~10,000-50,000 devices), plus a larger installed base used internally
CVE-2021-20045
A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as t

A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

NVD description · AI analysis pending
9.8
group max
25%
  • sonicwall sma 200 firmware
  • sonicwall sma 210 firmware
  • sonicwall sma 410 firmware
  • +1 more
Full article398 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 08, 2021

SonicWall strongly urges customers using SMA 100 series appliances to install security patches that address multiple security flaws, some of them rated as critical.

Security vendor SonicWall urges customers using SMA 100 series appliances to apply security patches that address multiple security vulnerabilities, some of which have been rated as critical.

“SonicWall has verified and patched vulnerabilities of critical and medium severity (CVSS 5.3-9.8) in SMA 100 series appliances, which include SMA 200, 210, 400, 410 and 500v products. SMA 100 series appliances with WAF enabled are also impacted by the majority of these vulnerabilities” reads the advisory published by the company. “SonicWall strongly urges that organizations follow the guidance below to patch SMA 100 series products, which include SMA 200, 210, 400, 410 and 500v appliances.”

Affected products are SMA 200, 210, 400, 410, and 500v appliances.

The most severe vulnerabilities addressed by SonicWall are two critical stack-based buffer overflow vulnerabilities tracked as CVE-2021-20038 and CVE-2021-20045 respectively. A remote attacker can trigger the two vulnerabilities to potentially execute as the ‘nobody’ user in compromised appliances.

“A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server’s mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a ‘nobody’ user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.” reads the advisory for the CVE-2021-20038 flaw.

SonicWall is not aware of attacks in the wild exploiting the following vulnerabilities.

Below is the full list of vulnerabilities that were reported by Jake Baines from Rapid7 and Richard Warren from NCC Group:

Issue IDSummaryCVECVSSReporting Party
SMA-3217Unauthenticated Stack-Based Buffer OverflowCVE-2021-200389.8Rapid7
SMA-3204Authenticated Command InjectionCVE-2021-200397.2Rapid7
SMA-3206Unauthenticated File Upload Path TraversalCVE-2021-200406.5Rapid7 |NCCGroup
SMA-3207Unauthenticated CPU ExhaustionCVE-2021-200417.5Rapid7
SMA-3208Unauthenticated Confused DeputyCVE-2021-200426.3Rapid7
SMA-3231Heap-Based Buffer OverflowCVE-2021-200438.8NCCGroup
SMA-3233Post-Authentication Remote Command ExecutionCVE-2021-200447.2NCCGroup
SMA-3235Multiple Unauthenticated Heap-Based and Stack Based Buffer OverflowCVE-2021-200459.4NCCGroup

The company said that there are no temporary mitigations for the above issues.

Experts pointed out that a high severity Authenticated command injection vulnerability, tracked as CVE-2021-20039, has yet to be addressed.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Apple)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/125400/security/sonicwall-sma-100-devices-flaws.html