Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Alert: More than 178,000 SonicWall firewalls may be vulnerable to attack
    Cyber Security

    Alert: More than 178,000 SonicWall firewalls may be vulnerable to attack

    techempireBy techempire3 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 16, 2024Editorial DepartmentVulnerabilities/Cyber ​​Security

    SonicWall Firewall

    More than 178,000 SonicWall firewalls exposed over the network are vulnerable to at least two security vulnerabilities that could be exploited to cause a denial of service (DoS) condition and remote code execution (RCE).

    Jon Williams, a senior security engineer at Bishop Fox, said in a technical analysis shared with The Hacker News: “The two issues are essentially the same, but can be exploited across different HTTP servers due to the reuse of vulnerable code patterns. Exploited on the URI path.”

    Internet security

    The vulnerabilities in question are listed below –

    • CVE-2022-22274 (CVSS Rating: 9.4) – A stack-based buffer overflow vulnerability in SonicOS via HTTP requests could allow an unauthenticated remote attacker to cause a DoS or possibly code execution within the firewall.
    • CVE-2023-0656 (CVSS Rating: 7.5) – A stack-based buffer overflow vulnerability in SonicOS allows an unauthenticated remote attacker to cause a DoS, potentially leading to a crash.

    While there have been no reports of these flaws being exploited in the wild, the SSD Secure Disclosure team released a proof-of-concept (PoC) for CVE-2023-0656 in April 2023.

    Cybersecurity firms revealed that these issues could be exploited by bad actors to cause repeated crashes and force devices into maintenance mode, requiring administrative action to restore normal functionality.

    “Perhaps most surprising, more than 146,000 publicly accessible devices are vulnerable to a vulnerability released two years ago,” Williams said.

    Internet security

    watchTowr Labs has discovered multiple stack-based buffer overflow flaws in the SonicOS management web interface and SSL VPN portal that can cause firewall crashes.

    To prevent possible threats, it is recommended to update to the latest version and ensure that the management interface is not exposed on the network.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.