ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds 15 flaws to the Known Exploited Vulnerabilities Catalog

highExploit / PoC exploited in the wildimportance 60CVE-2020-5135

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-5135
Buffer Overflow in SonicWall SonicOS Enables DoS and Potential RCE on Firewalls

CVE-2020-5135 is a buffer overflow vulnerability (CWE-120) in SonicWall's SonicOS firewall operating system. A remote attacker can trigger the flaw by sending a maliciously crafted request to a firewall running SonicOS, which can crash network services and cause a Denial of Service, with potential for arbitrary code execution. Because SonicOS runs on SonicWall perimeter firewalls and remote-access gateways, successful code execution would give an attacker a foothold at the network edge, a high-value position for both DoS and follow-on compromise. Any organization operating a SonicWall firewall running SonicOS is potentially affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, and EPSS estimates a 26.9% probability of exploitation within 30 days (98th percentile), indicating active and elevated exploitation risk even though no public PoC is known.

Do: Apply updated SonicOS firmware per SonicWall's instructions, as required by the CISA KEV listing, and confirm against SonicWall's advisory which firmware versions fix CVE-2020-5135 for your appliance. Until patched, restrict firewall management and remote-access (SSL-VPN) interfaces to trusted networks rather than the open internet. Given known ransomware use, hunt for signs of exploitation such as firewall crashes/reboots and anomalous outbound or lateral activity.

9.827% KEV ransomware
  • SonicWall SonicOS
mass≈ hundreds of thousands of internet-exposed SonicWall firewalls/remote-access endpoints
Full article220 words · extracted from securityaffairs.com · click to collapse

The US Cybersecurity and Infrastructure Security Agency (CISA) added 15 new flaws to its Known Exploited Vulnerabilities Catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 15 vulnerabilities to its Known Exploited Vulnerabilities Catalog.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

The new vulnerabilities added to the catalog include one SonicWall SonicOS issue, tracked as CVE-2020-5135, and 14 Microsoft Windows flaws addressed between 2016 and 2019.

The CVE-2020-5135 is a stack-based buffer overflow that affects the SonicWall Network Security Appliance (NSA). The vulnerability can be exploited by an unauthenticated HTTP request involving a custom protocol handler.

The flaw resides in the HTTP/HTTPS service used for product management as well as SSL VPN remote access.

All the flaws added in this round have to be addressed by federal agencies by April 5.

The CISA Catalog has reached a total of 504 entries with the latest added issues.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Cisa)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/129120/security/catalog-of-actively-exploited-2.html