Target Industry

Indiscriminate, opportunistic targeting.

Overview

The vulnerability known as CVE-2021-20035 that was previously patched in September 2021 has been further exploited since originally only being able to perform denial of service (DoS) attacks. This development of the exploit allows the threat actor to conduct remote code execution (RCE) on the vulnerable device, increasing the CVSS score from medium to high and resulting in more severe impacts. This affects SonicWall VPN SMA series which can be critical to organisations’ operations and access to sensitive data. The vulnerability is being exploited in the wild, according to the Cybersecurity Infrastructure and Security Agency (CISA), who will be adding it to their Known Exploited Vulnerabilities Catalog 

Impact

If the threat actor is successfully able to perform CVE-2021-20035 it will lead to the device being vulnerable to the already discovered DoS flaw. This will cause operational outage due to staff being unable to access the company network and applications, which is highly likely to lead to financial loss. If the threat actor is able to achieve further exploitation of RCE on the flawed device, this will lead to the threat actor having control over VPN, allowing them potential access to authorised only applications. This can lead to data theft and further operational disruption. 

Affected Products

Linux and macOS systems are primary targets of UNC6174 along with network devices, such as routers, switches, and firewalls, especially those from vendors like Ivanti and F5, are at risk. 

Exploitation

This exploit is achieved by a command injection by inputting special characters into the management panel. This will lead to RCE, allowing the attacker to have a large impact on the organisation.  

Vulnerability Detection

Current vulnerable products: 

  • SMA 200 
  • SMA 210 
  • SMA 400 
  • SMA 410 
  • SMA 500v (ESX, KVM, AWS, Azure). 

Vulnerable versions: 

  • 10.2.1.0-17sv and earlier 
  • 10.2.0.7-34sv and earlier  
  • 9.0.0.10-28sv and earlier  

Containment, Mitigations & Remediations

To mitigate, prevent and remediate potential issues: 

  • Restrict access: Limit access to the VPN appliances to trusted IP addresses and use strong authentication methods to reduce the risk of unauthorised access  
  • Update software: make sure all SMA series are of the latest version and not below the listed versions mentioned above 
  • Monitor SMA devices and networks for unusual activity if the device isn’t already patched to the secure versions. 

Threat Landscape

SonicWall products, including SMA 100 series, are widely deployed in enterprise environments across various sectors, including government, healthcare, financial services, energy, and education. These solutions enable secure remote access and support for zero-trust access frameworks, making them high-value targets for cybercriminals. 

Threat Group

There is currently no information available on which threat groups are exploiting this vulnerability. 

Tactics, Techniques, and Procedures

  • T1059.004 – Command and Scripting Interpreter – Unix Shell 
  • T1499 Denial-of-Service  
  • T1190 – Exploit Public-Facing Application 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content