Target Industry

Indiscriminate, opportunistic targeting.

Overview

In a concerning turn of events, ransomware affiliates are now exploiting a critical security vulnerability in SonicWall SonicOS firewall devices to breach victims’ networks. This vulnerability, tracked as CVE-2024-40766, has been identified as an improper access control flaw affecting Gen 5, Gen 6, and Gen 7 firewalls.

SonicWall initially addressed this issue by releasing a patch on 22nd August, cautioning that the vulnerability primarily impacted the firewalls’ management access interface. At the time, this contained the problem, offering a straightforward solution for affected users.

However, last Friday, 6th September, SonicWall dropped a crucial update: the same vulnerability also impacts the firewalls’ SSLVPN feature, and it is now being actively exploited in ransomware attacks. This revelation has significantly heightened the stakes, making it imperative for all SonicWall users to revisit their security measures.

SonicWall’s message to customers is clear and urgent: “Apply the patch as soon as possible for affected products.” While the company has not divulged specifics regarding the ongoing exploitation in the wild, the warning underscores the critical nature of the threat.

Impact

SonicWall serves over 500,000 business customers across 215 countries and territories, including government agencies and some of the world’s largest companies.

Successful exploitation of CVE-2024-40766 enables threat actors to initially compromise SSLVPN user accounts on SonicWall devices.

Containment, Mitigations & Remediations

SonicWall’s mitigation recommendations emphasise the importance of restricting firewall management and SSLVPN access to trusted sources and disabling internet access whenever possible.

Additionally, administrators are advised to enable multi-factor authentication (MFA) for all SSLVPN users, utilising TOTP or email-based one-time passwords (OTPs) to enhance security.

It is highly recommended that all organisations run the relevant patches as soon as possible. These security updates have been made available for download through mysonicwall.com:

  • For Gen 5: Version 5.9.2.14-13o
  • For Gen 6: Version 6.5.4.15.116n
  • For SM9800, NSsp 12400, and NSsp 12800, version 6.5.2.8-2n is safe
  • For Gen 7: Any SonicOS firmware version higher than 7.0.1-5035

Indicators of Compromise

No indicators of compromise (IoCs) are available currently.

Threat Landscape

Ransomware affiliates, including those behind Akira ransomware, have swiftly moved to exploit this vulnerability. By compromising SSLVPN user accounts, they gain initial access to networks, deploy ransomware, and demand significant ransoms. This method underscores the high value placed on such vulnerabilities by threat actors.

Threat Group

The cyber security landscape is facing an escalating threat as multiple ransomware gangs, including HelloKitty and FiveHands, have been exploiting security vulnerabilities in SonicWall devices to infiltrate corporate networks. Adding to this list, the Akira ransomware group has also started leveraging these SonicWall bugs to gain initial access to victims’ systems.

Further information

Bleeping Computer article

Security Week article

The Hacker News article

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content