
THREAT LEVEL - HIGH
10-09-2024
New Critical SonicWall Vulnerability Under Active Exploitation
Threat Level Description
IthacaLabs has maintained the Threat Level (High) adding a new observation:
Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.
Description
We have observed that a new critical vulnerability impacting SonicWall’s SonicOS has been identified.
An attacker, by exploiting this vulnerability, could gain unauthorized access to system resources and, in certain conditions, cause the firewall to crash.
The vulnerability, tracked as CVE-2024-40766, is an improper access control issue affecting SonicWall’s SonicOS management access and SSLVPN services.
SonicWall has confirmed that this vulnerability may have been actively exploited in the wild. While specific details of the exploitation are not yet available, there is historical evidence of Chinese threat actors targeting unpatched SonicWall devices, such as the Secure Mobile Access (SMA) 100 appliances, to establish long-term persistence in compromised networks.
CVE(s)
CVE-2024-40766,
Affected Systems
- SOHO (Gen 5 Firewalls): Firmware version 5.9.2.14-13o
- Gen 6 Firewalls:
- Firmware version 6.5.2.8-2n (for SM9800, NSsp 12400, and NSsp 12800)
- Firmware version 6.5.4.15.116n (for other Gen 6 Firewall appliances)
Recommendation(s)
You should proceed to apply all security patches provided by the vendor immediately.
While applying patches is the primary recommendation, there are several temporary workarounds that can help mitigate the risk of exploitation until patches are fully deployed:
- Restrict Firewall Management Access: Limit management access to trusted IP addresses or internal networks. If possible, disable WAN management to prevent firewall management interfaces from being accessed over the internet.
- SSLVPN Access Control: Restrict SSLVPN access to trusted sources only. If feasible, consider disabling SSLVPN access entirely from the internet to minimize exposure to attacks.
- Enable Multi-Factor Authentication (MFA): Enable MFA for all SSLVPN users, preferably using one-time passwords (OTPs). This adds an additional layer of security, even in the event that login credentials are compromised.
- Immediate Password Updates: For organizations using GEN5 and GEN6 firewalls with SSLVPN users, particularly those with locally managed accounts, it is strongly advised to immediately update all passwords. This will help mitigate the risk of unauthorized access, especially if login credentials have already been exposed or are vulnerable.
You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.
References:



