Ransomware attackers are leveraging old SonicWall SRA flaw (CVE-2019-7481)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-7481 | Unauthenticated SQL Injection in SonicWall SMA100 Appliances SonicWall SMA100 secure-access appliances contain a SQL injection flaw (CWE-89) that requires no authentication to exploit. A remote attacker sends crafted input to the vulnerable appliance, most plausibly through its internet-facing web/remote-access interface, and gains read-only access to resources they are not authorized to see. An attacker is therefore limited to reading unauthorized data, but the flaw provides unauthenticated access to a network edge device and a basis for further reconnaissance. Any organization running a SonicWall SMA100 appliance — typically deployed as an internet-exposed SSL-VPN/remote-access gateway — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use noted, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile). Do: Apply firmware updates to SMA100 appliances per SonicWall's instructions, as CISA's required action states and no fixed version is given in this data. Because CISA notes known ransomware use, prioritize patching any internet-exposed SMA device, review appliance and firewall logs for unexpected unauthenticated access, and as an interim mitigation restrict exposure of the appliance's web interface to trusted source addresses. | 7.5 | 100% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed SMA100/SSL-VPN appliances |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 9.0.0.5 | All organizations used SonicWall SRA VPN appliances running 9.0.0.5 firmware,” researchers Heather Smith and Hanno Heinrichs no |
Full article389 words · extracted from helpnetsecurity.com · click to collapse
Since the beginning of the year, various cyber attackers leveraged a slew of zero-day vulnerabilities to compromise different SonicWall solutions. Crowdstrike now warns that a cyber-criminal group is exploiting CVE-2019-7481 – an older SQL injection vulnerability affecting SonicWall Secure Remote Access (SRA) 4600 devices running firmware versions 8.x and 9.x – to penetrate organizations’ networks.

“In some recent investigations, CrowdStrike’s Incident Response team has had correlative evidence indicating a root cause via VPN access without brute forcing. These investigations have a common denominator: All organizations used SonicWall SRA VPN appliances running 9.0.0.5 firmware,” researchers Heather Smith and Hanno Heinrichs noted.
Why is this happening?
VPN devices have become a mainstay for organizations looking to provide remote employees with contolled access needed to do their jobs – as well as a favorite target for both cyber criminals and nation-state actors.
Support for SonicWall SRA 4600 devices ended on 1 November 2019 and, since then, the company has been advising customers to upgrade to a newer, supported device line (Secure Mobile Access – SMA). But we all know that unsupported devices are often not promptly replaced, so the SonicWall PSIRT also told customers that older SRA devices could be patched by implementing SMA firmware updates.
Unfortunately, it turns out that firmware version 9.0.0.5, the recommended patch prescribed for SMA devices in 2019, did not fix CVE-2019-7481 in SRA devices.
With public proof of concept and code being available for this flaw, it’s no wonder that attackers attempted to leverage it.
What should you do?
Companies that still run SRA devices should check which firmware version they are using and check their logs for indicators of compromise.
“While SonicWall’s recommendation is to upgrade any legacy SRA devices to the 10.x versioning recommended in light of the 2021 zero-day disclosure, CrowdStrike would additionally recommend that organizations consider replacing any legacy models for newer devices that are in-scope for vendor testing and support,” the researchers added.
Aside from that, they advise organizations to protecting VPN access and other apps, portals and email open to remote access with multi-factor authentication, and to implement endpoint detection and response (EDR) software to stymie attackers that might pass that first barrier.
UPDATE – June 15, 2021, 01:12 p.m. PT
The names of the authors of the Crowdstrike blog post referenced in the article have been added.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/06/14/cve-2019-7481/