ZeroHour
The Recordpublished ()ingested

Ransomware gangs are increasingly going after SonicWall devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-7481
Unauthenticated SQL Injection in SonicWall SMA100 Appliances

SonicWall SMA100 secure-access appliances contain a SQL injection flaw (CWE-89) that requires no authentication to exploit. A remote attacker sends crafted input to the vulnerable appliance, most plausibly through its internet-facing web/remote-access interface, and gains read-only access to resources they are not authorized to see. An attacker is therefore limited to reading unauthorized data, but the flaw provides unauthenticated access to a network edge device and a basis for further reconnaissance. Any organization running a SonicWall SMA100 appliance — typically deployed as an internet-exposed SSL-VPN/remote-access gateway — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use noted, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile).

Do: Apply firmware updates to SMA100 appliances per SonicWall's instructions, as CISA's required action states and no fixed version is given in this data. Because CISA notes known ransomware use, prioritize patching any internet-exposed SMA device, review appliance and firewall logs for unexpected unauthenticated access, and as an interim mitigation restrict exposure of the appliance's web interface to trusted source addresses.

7.5100% KEV ransomware
  • SonicWall SMA100
largeon the order of tens of thousands of internet-exposed SMA100/SSL-VPN appliances
CVE-2021-20016
Unauthenticated SQL Injection in SonicWall SMA100 SSL VPN

CVE-2021-20016 is an unauthenticated SQL injection flaw (CWE-89) in the SonicWall SSL-VPN service on SMA 100 appliances. It is triggered remotely by malicious, unauthenticated requests to the appliance's web interface, allowing SQL injection against the backend database. Successful exploitation gives the attacker credential access — harvesting valid user credentials that can then be used to log into the SSL-VPN and pivot into the victim network. Any organization running an internet-facing SonicWall SSLVPN SMA100 appliance is affected, and CISA notes known ransomware use of this flaw. It was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 40% EPSS probability of exploitation within 30 days (99th percentile), so it should be treated as actively exploited even though no public proof-of-concept is known.

Do: Apply the SonicWall firmware update per vendor instructions, as required by the CISA KEV listing. Because ransomware operators are known to exploit this flaw, review SMA100 authentication and admin logs for unfamiliar logins, rotate exposed credentials, and restrict the appliance to trusted source IPs until it is patched. CVSS has not yet been scored, but the 40% EPSS (99th percentile) and KEV status warrant immediate patching of all internet-exposed units.

9.840% KEV ransomware
  • SonicWall SSLVPN SMA100
large≈ tens of thousands of internet-exposed SMA100 appliances (public scan counts of SonicWall SSL-VPN endpoints)
Full article516 words · extracted from therecord.media · click to collapse

Over the course of the last few months, cybercrime groups have increasingly targeted SonicWall devices in order to breach corporate networks and deploy ransomware.

The attacks come after enterprise-grade networking equipment from Citrix, F5, Pulse Secure, Fortinet, and Palo Alto Networks was abused in a similar manner across 2019 and 2020, with enterprise VPNs and network gateways representing a popular entry point for ransomware gangs.

But as these systems got patched, cybercrime groups also started looking for the next equipment they could target.

According to reports published in April (by Mandiant) and this week (by CrowdStrike), threat actors appear to have found a new target in SonicWall devices.

Per the two reports, during the first half of the year, threat actors scanned the internet and relied on exploits for two vulnerabilities to hijack SonicWall equipment.

This included attacks against SonicWall SRA VPN servers using an older 2019 exploit (CVE-2019-7481) and attacks against SonicWall SMA network gateways using a bug that was patched in February this year (CVE-2021-20016).

Final payloads in these attacks included the HelloKitty, FiveHands, and Darkside ransomware strains, according to Mandiant.

However, taking into account how often ransomware gangs jump from one Ransomware-as-a-Service (RaaS) affiliate program to another, detecting the final payload in these attacks is often counterproductive.

Instead, in a blog post on Tuesday, CrowdStrike urged companies to apply patches or at least add two-factor authentication support to SonicWall systems.

Successful attacks spotted against already-patched systems

Furthermore, Crowdstrike researchers Heather Smith and Hanno Heinrichs also said they observed successful attacks leveraging the 2019 bug against already-patched devices, running SRA VPN firmware version 9.0.0.5, suggesting the threat actors found a way to bypass SonicWall's initial fixes.

But, there is also some good news for companies still using the older legacy SRA VPN devices. Crowdstrike said that SonicWall SRA VPN owners could apply the 10.x firmware versions, which are compatible with older devices and which SonicWall released this February after the CVE-2021-20016 vulnerability was used against its own internal network.

Nevertheless, the security firm suggested that companies also look into replacing the older SRA VPN equipment with newer devices, which are supported and receive patches on a more regular basis.

The gist here is that there's been a significant shift in threat actor operations since 2019, when ransomware gangs seem to have abandoned spear-phishing email-based attacks in favor of targeting edge networking devices. Since then, these attacks have become widespread and have been used by all types of threat actors, such as nation-state groups and not just ransomware gangs.

While some threat actors seem to target SonicWall devices for this particular stretch, they are also very likely to go after similar equipment from other enterprise vendors as well once a major vulnerability is discovered in their firmware that can be exploited remotely over the internet.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ransomware-gangs-are-increasingly-going-after-sonicwall-devices