A critical stack-based Buffer Overflow vulnerability has been discovered in SonicWall VPNs.
When exploited, it allows unauthenticated remote attackers to execute arbitrary code on the impacted devices.
Tracked as CVE-2020-5135, the vulnerability impacts multiple versions of SonicOS ran by hundreds of thousands of active VPNs.
Craig Young of Tripwire Vulnerability and Exposure Research Team (VERT) and Nikita Abramov of Positive Technologies have been credited with discovering and reporting the vulnerability.
Shodan lists over 800,000 devices
Given an increase in employees working remotely and the reliance on corporate VPNs, easily exploitable flaws like these are concerning when it comes to security.
As confirmed by Tenable researchers and observed by BleepingComputer, as of today, Shodan shows over 800,000 VPN devices running vulnerable SonicOS software versions, depending on the search term used.
Although a Proof-of-Concept (POC) exploit is not yet available in the wild, the vast attack surface available to adversaries means companies should upgrade their devices immediately.
Impacted versions and remediation guidance
The following SonicWall VPN devices are impacted by CVE-2020-5135:
- SonicOS 220.127.116.11-79n and earlier
- SonicOS 18.104.22.168-4n and earlier
- SonicOS 22.214.171.124-93o and earlier
- SonicOSv 126.96.36.199-44v-21-794 and earlier
- SonicOS 188.8.131.52-1
“SonicWall has released updates to remediate this flaw. SSL VPN portals may be disconnected from the Internet as a temporary mitigation before the patch is applied,” stated Tripwire VERT’s advisory.
The following versions are available to upgrade to for safeguarding against this vulnerability:
- SonicOS 184.108.40.206-83n
- SonicOS 220.127.116.11-1n
- SonicOS 18.104.22.168-94o
- SonicOS 6.5.4.v-21s-987
- Gen 7 22.214.171.124-2 and onwards
Provided the vast number of devices that are still running the outdated SonicOS versions and the critical nature of this vulnerability, complete research findings on CVE-2020-5135 are expected to be released once enough users have patched their systems.
SonicWall has provided BleepingComputer with a statement regarding the vulnerability:
“SonicWall maintains the highest standards to ensure the integrity of its products, solutions, services, technology and any related IP. As such, the company takes every disclosure or discovery seriously.”
“SonicWall was contacted by a third-party research team regarding issues related to SonicWall next-generation virtual firewall models (6.5.4v) that could potentially result in Denial-of-Service (DoS) attacks and/or cross-site scripting (XSS) vulnerabilities.”
“Immediately upon discovery, SonicWall researchers conducted extensive testing and code review to confirm the third-party research. This analysis lead to the discovery of additional unique vulnerabilities to virtual and hardware appliances requiring Common Vulnerabilities and Exposures (CVE) listings based on the Common Vulnerability Scoring System (CVSS). The PSIRT team worked to duplicate the issues and develop, test and release patches for the affected products. At this time, SonicWall is not aware of a vulnerability that has been exploited or that any customer has been impacted,” the company told BleepingComputer.
Update—Oct 16, 2020: Added statement from SonicWall.
To read the original article: