• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
Computer Business World News

Computer Business World News

Trending News about Computers, Business and Tech

  • Home
  • BUSINESS
  • CAREERS
  • CLOUD
  • COMPUTERS
  • CYBERSECURITY
  • I.T.
  • TECH
  • VOIP
  • About

Patch these SonicWall zero-days now, customers warned Zero-day attack

by

Cybersecurity solutions provider SonicWall has asked businesses using its Email Security (ES) products to upgrade to the latest version in order to mitigate a set of serious zero-day vulnerabilities.

Researchers at security firm Mandiant Managed Defense were first to identify the three vulnerabilities, which were being actively exploited in the wild. In a blog post, the researchers described the attack made possible by the vulnerabilities.

They note that the flaws were chained and executed in conjunction by the threat actors in order to gain administrative access and code execution permissions on a SonicWall ES device.

TechRadar needs you!

We’re looking at how our readers use VPN for a forthcoming in-depth report. We’d love to hear your thoughts in the survey below. It won’t take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

The good news, though, is that all three vulnerabilities have now been patched.

“It is imperative that organizations using SonicWall Email Security hardware appliances, virtual appliances or software installation on Microsoft Windows Server immediately upgrade to the respective SonicWall Email Security version,” said SonicWall.

Complex attack

One of the vulnerabilities, tracked as CVE-2021-20021, has a very high Common Vulnerability Scoring System (CVSS) rating of 9.4/10, as it can be exploited to create an administrative account by sending a crafted HTTP request to the remote host.

Mandiant researchers became aware of the vulnerabilities while investigating a post-exploitation backdoor in a customer’s SonicWall Email Security instance running atop a Windows Server 2012 installation.

They note that the attackers had intimate knowledge of the SonicWall application and used a combination of all the three exploits interchangeably to not just install a backdoor, but also access files and emails, and traverse the victim organization’s network.

SonicWall, for its part, has provided step-by-step instructions to enable its customers to apply the security update in order to mitigate the vulnerabilities.

Update:

A SonicWall spokesperson has since provided TechRadar Pro with the following statement:

“SonicWall routinely collaborates with third-party researchers and forensic analysis firms to ensure that our products meet or exceed security best practices. Through the course of this process, SonicWall was made aware of and verified certain zero-day vulnerabilities to its hosted and on-premises email security products. SonicWall designed, tested and published patches to correct the issues and communicated these mitigations to customers and partners.”
 
“SonicWall strongly encourages customers — as well as organizations worldwide — to maintain diligence in patch management to strengthen the community’s collective security posture.”

View Source

Filed Under: COMPUTERS

Primary Sidebar

More to See

PCI Pal Extends Patent Portfolio in US and Australia for Processing Sensitive Information over VoIP

CHARLOTTE, N.C.--(BUSINESS WIRE)--PCI Pal® (LON: PCIP), the global cloud provider of secure payment solutions, has been granted further patents in … [Read More...] about PCI Pal Extends Patent Portfolio in US and Australia for Processing Sensitive Information over VoIP

One car, two stolen semi-truck computers, & two wanted

LANSING, Mich. (WLNS) — The Crime Stoppers of Mid-Michigan are staying busy this week, with four different cases that they need your help with. Two … [Read More...] about One car, two stolen semi-truck computers, & two wanted

Cloud Computing Data Center IT Asset Disposition Market Size, Scope, Revenue, Opportunities and Growth by 2028 – Shanghaiist

New Jersey, United States – Verified Market Research recently released a new report titled Cloud Computing Data Center IT Asset Disposition Market … [Read More...] about Cloud Computing Data Center IT Asset Disposition Market Size, Scope, Revenue, Opportunities and Growth by 2028 – Shanghaiist

Footer

SITE INFORMATION

COMPUTER BUSINESS WORLD NEWS

About/Contact

Privacy Policy

Thank you for visiting our website.

Recent

  • NFT and Metaverse Scams: Cybersecurity
  • PCI Pal Extends Patent Portfolio in US and Australia for Processing Sensitive Information over VoIP
  • One car, two stolen semi-truck computers, & two wanted

Search

Copyright © 2022 Computer Business World