Tag Archive for: SonicWALL

SonicWall Investigating Zero-Day Attacks Against Its Products


Application Security
,
Breach Notification
,
Cybercrime as-a-service

Company Says Certain VPNs and Gateways Affected By ‘Coordinated Attack’

SonicWall Investigating Zero-Day Attacks Against Its Products
A zero-dat attack is affecting SonicWall’s SMA 100 series gateway products (Source: SonicWall)

Security vendor SonicWall is investigating what the company calls a “coordinated attack” against its internal network by threat actors using a zero-day exploit within the company’s remote access products.

See Also: 2020 Trust Report: Measuring the Value of Security Amidst Uncertainty


In a short statement posted to customers, SonicWall says it is continuing to investigate the incident and that users of certain versions of its Secure Mobile Access (SMA) gateway products should apply temporary fixes until a permanent patch is available.


And while SonicWall did not release details about the zero-day attack and the vulnerability, the company stressed that this security incident appears well planned.


“Recently, SonicWall identified a coordinated attack on its internal systems by highly sophisticated threat actors exploiting probable zero-day vulnerabilities on certain SonicWall secure remote access products,” according to the company statement released Friday.


On Saturday, SonicWall released an updated statement, which detailed a number of products not affected by the attack. This includes the NetExtender VPN Client access product, which the firm originally believed had been targeted…

Source…

SonicWall firewall maker hacked using zero-day in its VPN device


SonicWall

Security hardware manufacturer SonicWall has issued an urgent security notice about threat actors exploiting a zero-day vulnerability in their VPN products to perform attacks on their internal systems.

SonicWall is a well-known manufacturer of hardware firewall devices, VPN gateways, and network security solutions whose products are commonly used in SMB/SME and large enterprise organizations.

On Friday night, SonicWall released an ‘urgent advisory’ stating that hackers used a zero-day vulnerability in their Secure Mobile Access (SMA) VPN device and its NetExtender VPN client in a “sophisticated” attack on their internal systems.

“Recently, SonicWall identified a coordinated attack on its internal systems by highly sophisticated threat actors exploiting probable zero-day vulnerabilities on certain SonicWall secure remote access products,” states SonicWall’s security notice published late Friday night.

SonicWall states that the impacted products are:

  • NetExtender VPN client version 10.x (released in 2020) utilized to connect to SMA 100 series appliances and SonicWall firewalls
  • Secure Mobile Access (SMA) version 10.x running on SMA 200, SMA 210, SMA 400, SMA 410 physical appliances and the SMA 500v virtual appliance

Secure Mobile Access (SMA) is a physical device that provides VPN access to internal networks, while the NetExtender VPN client is a software client used to connect to compatible firewalls that support VPN connections.

SonicWall states that customers can protect themselves by enabling multi-factor authentication (MFA) on affected devices and restricting access to devices based on whitelisted IP addresses.

FOR SMA 100 SERIES

  • Use a firewall to only allow SSL-VPN connections to the SMA appliance from known/whitelisted IPs
  • Or configure whitelist access on the SMA directly itself

FOR FIREWALLS WITH SSL-VPN ACCESS VIA NETEXTENDER VPN CLIENT VERSION 10.X

  • Disable NetExtender access to the firewall(s) or restrict access to users and admins via an allow-list/whitelist for their public IPs

MFA MUST BE ENABLED ON ALL SONICWALL SMA, FIREWALL & MYSONICWALL ACCOUNTS

SonicWall has not released detailed information about the zero-day vulnerabilities. Based on the mitigation steps,…

Source…

Mid-year 2019 SonicWall Cyber Threat Report outlines major spikes in various threats – ITWeb

Mid-year 2019 SonicWall Cyber Threat Report outlines major spikes in various threats  ITWeb

SonicWall’s mid-year 2019 SonicWall Cyber Threat Report has cited an alarming 76% and 55% spike in encrypted and IOT attacks respectively. The company …

“exploit kit” – read more