Artificial Intelligence | News | Insights | AiThority
[bsfp-cryptocurrency style=”widget-18″ align=”marquee” columns=”6″ coins=”selected” coins-count=”6″ coins-selected=”BTC,ETH,XRP,LTC,EOS,ADA,XLM,NEO,LTC,EOS,XEM,DASH,USDT,BNB,QTUM,XVG,ONT,ZEC,STEEM” currency=”USD” title=”Cryptocurrency Widget” show_title=”0″ icon=”” scheme=”light” bs-show-desktop=”1″ bs-show-tablet=”1″ bs-show-phone=”1″ custom-css-class=”” custom-id=”” css=”.vc_custom_1523079266073{margin-bottom: 0px !important;padding-top: 0px !important;padding-bottom: 0px !important;}”]

Positive Technologies Helps Fix 11 Vulnerabilities in Popular SonicWall Firewall Appliances

SonicWall  Potential threats included disconnection of remote employees or branches and possible attacker penetration into corporate networks

SonicWall patched vulnerabilities in SonicOS for firewall appliances discovered by Positive Technologies expert Nikita Abramov. According to IDC, SonicWall ranks fifth among manufacturers of gateway security appliance solutions worldwide. 

The most serious vulnerability, CVE-2020-5135, found by Nikita Abramov at Positive Technologies and Craig Young at Tripwire, is of critical severity (CVSS v3 score 9.4). This buffer overflow vulnerability in SonicOS allows remote attackers to cause denial of service (DoS) and potentially execute arbitrary code.

Recommended AI News: Converge Technology Solutions Achieves Titanium Partner Status with Dell Technologies

Nikita Abramov researcher at Positive Technologies explained: “The tested solution uses a SSL-VPN remote access service on firewalls, and users can be disconnected from internal networks and their workstations in case of a DoS attack. If attackers manage to execute arbitrary code, they may be able to develop an attack and penetrate the company’s internal networks.”

“This is best practice for vendor-researcher collaboration in the modern era,” said SonicWall’s Aria Eslambolchizadeh, Head of Quality Engineering. “These types of open and transparent relationships protect the integrity of the online landscape, and ensure better protection from advanced threats and emerging vulnerabilities before they impact end users, as was the case here.”

Related Posts
1 of 16,731

CVE-2020-5135 affects SonicOS 6.5.4.7-79n, SonicOS 6.5.1.11-4n, SonicOS 6.0.5.3-93o and SonicOSv 6.5.4.4-44v-21-794 (including older versions). To fix CVE-2020-5135, users need to upgrade to the following firmware versions (depending on their product): SonicOS 6.5.4.7-83n, SonicOS 6.5.1.12-1n, SonicOS 6.0.5.3-94o or SonicOS 6.5.4.v-21s-987.

Another vulnerability, CVE-2020-5133, received a CVSS v3 score of 8.2. This vulnerability allows a remote unauthenticated attacker to cause denial of service attacks due to buffer overflow, which leads to a firewall crash.

Recommended AI News: NVIDIA Smashes Performance Records on AI Inference

Failures in SonicOS can also be caused by exploitation of vulnerabilities CVE-2020-5137, CVE-2020-5138, CVE-2020-5139, and CVE-2020-5140 (all of them have a CVSS v3 score of 7.5 and can be exploited by remote unauthenticated attackers), and vulnerabilities CVE-2020-5134 and CVE-2020-5136 (CVSS v3 score 6.5, exploitation requires authentication).

In addition, a remote unauthenticated attacker can bruteforce Virtual Assist ticket ID in the SSL-VPN service (vulnerability CVE-2020-5141, CVSS v3 score 6.5). A cross-site scripting (XSS) vulnerability CVE-2020-5142 (CVSS v3 score 6.5) allows a remote unauthenticated attacker to potentially execute arbitrary JavaScript code in the firewall SSL-VPN portal. Finally, a SonicOS SSL-VPN login page could allow a remote unauthenticated attacker to perform firewall management administrator username enumeration based on the server responses (vulnerability CVE-2020-5143, CVSS v3 score 5.3).

Recommended AI News: Luminoso Expands Product Leadership with Two New Hires

Leave A Reply

Your email address will not be published.