Attackers are now targeting an authentication bypass vulnerability affecting SonicWall firewalls shortly after the release of proof-of-concept (PoC) exploit code. This security flaw (CVE-2024-53704), tagged by CISA as critical severity and found in the SSLVPN authentication mechanism, impacts SonicOS versions 7.1.x (up to 7.1.1-7058), 7.1.2-7019, and 8.0.0-8035, used by multiple models of Gen 6 and Gen 7 firewalls and SOHO series devices. Successful exploitation enables remote attackers to hijack active SSL VPN sessions without authentication, which grants them unauthorized access to targets' networks. SonicWall urged customers to immediately upgrade their firewalls' SonicOS firmware to prevent exploitation in an email sent before disclosing the vulnerability publicly and releasing security updates on January 7. The company also shared mitigation measures for admins who couldn't immediately secure their devices, including limiting access to trusted sources and restricting access from the Internet entirely if not needed. On Thursday, cybersecurity company Arctic Wolf said they started detecting exploitation attempts targeting this vulnerability in attacks "shortly after the PoC was made public," confirming SonicWall's fears regarding the vulnerability's increased exploitation potential. "The released PoC exploit allows an unauthenticated threat actor to bypass MFA, disclose private information, and interrupt running VPN sessions," Arctic Wolf stated. "Given the ease of exploi...
SonicWall firewall bug targeted in attacks after PoC exploit release
BleepingComputer
·Sergiu Gatlan
·Published Feb 14, 2025
·Updated
Affected Software
6 affected components
SonicWall SonicOS=7.1.x
SonicWall SonicOS=7.1.2-7019
SonicWall SonicOS=8.0.0-8035
SonicWall SonicOS=7.1.x
SonicWall SonicOS=7.1.2-7019
SonicWall SonicOS=8.0.0-8035
Frequently Asked Questions
1
What vulnerability is being reported in the article?
The article reports on an authentication bypass vulnerability (CVE-2024-53704) affecting SonicWall firewalls.
2
What are the security implications of this vulnerability?
Attackers are actively exploiting this vulnerability, posing significant risks to systems using affected SonicWall products.
3
Which versions of SonicWall SonicOS are affected?
The affected versions include SonicOS 7.1.x, 7.1.2-7019, and 8.0.0-8035.
4
What actions should users of affected SonicWall products take?
Users should promptly apply any available patches or updates to mitigate the vulnerabilities.
5
Who has identified the vulnerability as critical?
The vulnerability has been tagged as critical by CISA, indicating its severity.