SonicWall Vulnerability in SMA 100 Series

Fortify Security Team
Feb 8, 2021

OVERVIEW:

A vulnerability has been discovered in the SonicWall SMA 100 Series, which could allow for SQL injection. The SonicWall SMA 100 Series is a unified secure access gateway that enables organizations to provide access to any application, anytime, from anywhere and any devices, including managed and unmanaged. Successful exploitation of this vulnerability could result in SQL injection, which enables the retrieval of admin credentials. Afterwards, this retrieval can pivot into a remote-code execution attack. Depending on the privileges associated with the application, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights.

THREAT INTELLIGENCE: There are currently reports of this vulnerability being exploited in the wild as per NCCGroup.

SYSTEMS AFFECTED:

  • SonicWall SMA 200, SMA 210, SMA 400, SMA 410
  • SonicWall SMA 500v (Azure, AWS, ESXi, HyperV)

RISK:
Government:

  • Large and medium government entities: High
  • Small government entities: High

Businesses:

  • Large and medium business entities: High
  • Small business entities: High

Home users: Low

TECHNICAL SUMMARY:

A vulnerability has been discovered in the SonicWall SMA 100 Series, which could allow for SQL injection. The improper SQL command neutralization in the SonicWall SSLVPN SMA100 product enables the execution of SQL commands of the attacker’s choosing.

Successful exploitation of this vulnerability could result in SQL injection, which enables the retrieval of admin credentials. Afterwards, this retrieval can pivot into a remote-code execution attack. Depending on the privileges associated with the application, an attacker could install programs; view, change, or delete data; or create new accounts with full user rights.

RECOMMENDATIONS:

We recommend the following actions be taken:

  • Apply the patched version of the SMA 10.x firmware to vulnerable systems immediately after appropriate testing.
  • Apply appropriate countermeasures recommended by SonicWall within their advisory
  • Apply the Principle of Least Privilege to all systems and services.

REFERENCES:
SonicWall:
https://www.sonicwall.com/support/product-notification/urgent-patch-available-for-sma-100-series-10-x-firmware-zero-day-vulnerability-updated-feb-3-2-p-m-cst/210122173415410/

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001

NCCGroup:
https://twitter.com/NCCGroupInfosec/status/1355850304596680705

Recent Posts

Karakurt Data Extortion Group

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of the Treasury (Treasury), and the Financial Crimes Enforcement Network (FinCEN) are releasing this joint Cybersecurity Advisory (CSA) to provide...

WatchGuard Firebox and XTM Could Allow for Remote Code Execution

Multiple vulnerabilities have been discovered in WatchGuard Firebox and XTM appliances, the most severe of which could allow for Remote code execution. WatchGuard Firebox is a unified security platform that gives IT professionals the network visibility tools to ensure...

Splunk Enterprise Servers Allow Arbitrary Code Execution

A vulnerability in Splunk Enterprise Deployment Servers Could Allow for Arbitrary Code Execution. Splunk Universal Forwarders, in which the vulnerability lies, are used to send data from a machine to a data receiver usually Splunk.  If an attacker is able to...

Cisco Email Security Appliance Allows for Authentication Bypass

A vulnerability in Cisco Email Security Appliance, Cisco Secure Email & Web Manager could Allow for an authentication bypass under specific conditions. Exploitation of this vulnerability could allow for an unauthenticated attacker to gain unauthorized access to...