SonicWall Urges Customers to Immediately Patch Critical SMA 100 Flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20038 | Unauthenticated Stack Buffer Overflow in SonicWall SMA 100 Appliances SonicWall SMA 100 series secure remote-access appliances contain an unauthenticated stack-based buffer overflow (CWE-121) in the appliance's network-facing interface, triggered by crafted requests sent to the device without any credentials. A remote attacker who triggers the overflow can execute arbitrary code on the appliance with the privileges of the affected service, gaining a foothold on an internet-facing VPN gateway that typically sits at the network edge. Any organization running an SMA 100 series appliance is affected, and because these appliances provide remote access to corporate networks, compromise can expose entire internal environments. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-01-28 with known ransomware use, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in the provided data, but the KEV listing and EPSS score indicate active attacker interest. Do: Upgrade SMA 100 series appliances to firmware 10.0.7.2 or later per SonicWall's instructions, as required by the CISA KEV listing. Until patched, restrict internet exposure of the SMA portal and management interface to trusted sources where feasible. Because ransomware operators are known to exploit this flaw, review appliance logs for signs of compromise and monitor for unexpected account creation or traffic after patching. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed SMA 100 appliances (order of magnitude ~10,000-50,000 devices), plus a larger installed base used internally | |
| CVE-2021-20045 | A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as t A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. NVD description · AI analysis pending | 9.8 group max | 25% |
| — |
Full article330 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 09, 2021
Network security vendor SonicWall is urging customers to update their SMA 100 series appliances to the latest version following the discovery of multiple security vulnerabilities that could be abused by a remote attacker to take complete control of an affected system.
The flaws impact SMA 200, 210, 400, 410, and 500v products running versions 9.0.0.11-31sv and earlier, 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier. The San Jose-based company credited security researchers Jake Baines (Rapid7) and Richard Warren (NCC Group) for discovering and reporting the shortcomings.
The list of eight security vulnerabilities identified in its remote access products is as follows -
- CVE-2021-20038 (CVSS score: 9.8) - SMA100 Series unauthenticated stack-based buffer overflow vulnerability
- CVE-2021-20039 (CVSS score: 7.2) - SMA 100 Series authenticated command injection vulnerability as root
- CVE-2021-20040 (CVSS score: 6.5) - SMA 100 Series unauthenticated file upload path traversal vulnerability
- CVE-2021-20041 (CVSS score: 7.5) - SMA 100 Series unauthenticated CPU exhaustion vulnerability
- CVE-2021-20042 (CVSS score: 6.3) - SMA 100 Series unauthenticated "Confused Deputy" vulnerability
- CVE-2021-20043 (CVSS score: 8.8) - SMA 100 Series "getBookmarks" heap-based buffer overflow vulnerability
- CVE-2021-20044 (CVSS score: 7.2) - SMA 100 Series post-authentication remote code execution (RCE) vulnerability
- CVE-2021-20045 (CVSS score: 9.4) - SMA 100 Series unauthenticated file explorer heap-based and stack-based buffer overflow vulnerabilities
Successful exploitation of the flaws could allow an adversary to execute arbitrary code, upload specially crafted payloads, modify or delete files located in specific directories, reboot system remotely, bypass firewall rules, and even consume all of the device's CPU, potentially causing a denial-of-service (DoS) condition.
While there is no evidence that these vulnerabilities are being exploited in the wild, it's highly recommended that users move quickly to apply the patches in light of the fact that SonicWall devices have become a lucrative target for threat actors to launch a slew of malicious actions in recent months.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/12/sonicwall-urges-customers-to.html