Target Industry
Indiscriminate, opportunistic targeting.
Overview
In a concerning turn of events, ransomware affiliates are now exploiting a critical security vulnerability in SonicWall SonicOS firewall devices to breach victims’ networks. This vulnerability, tracked as CVE-2024-40766, has been identified as an improper access control flaw affecting Gen 5, Gen 6, and Gen 7 firewalls.
SonicWall initially addressed this issue by releasing a patch on 22nd August, cautioning that the vulnerability primarily impacted the firewalls’ management access interface. At the time, this contained the problem, offering a straightforward solution for affected users.
However, last Friday, 6th September, SonicWall dropped a crucial update: the same vulnerability also impacts the firewalls’ SSLVPN feature, and it is now being actively exploited in ransomware attacks. This revelation has significantly heightened the stakes, making it imperative for all SonicWall users to revisit their security measures.
SonicWall’s message to customers is clear and urgent: “Apply the patch as soon as possible for affected products.” While the company has not divulged specifics regarding the ongoing exploitation in the wild, the warning underscores the critical nature of the threat.
Impact
SonicWall serves over 500,000 business customers across 215 countries and territories, including government agencies and some of the world’s largest companies.
Successful exploitation of CVE-2024-40766 enables threat actors to initially compromise SSLVPN user accounts on SonicWall devices.
Containment, Mitigations & Remediations
SonicWall’s mitigation recommendations emphasise the importance of restricting firewall management and SSLVPN access to trusted sources and disabling internet access whenever possible.
Additionally, administrators are advised to enable multi-factor authentication (MFA) for all SSLVPN users, utilising TOTP or email-based one-time passwords (OTPs) to enhance security.
It is highly recommended that all organisations run the relevant patches as soon as possible. These security updates have been made available for download through mysonicwall.com:
- For Gen 5: Version 5.9.2.14-13o
- For Gen 6: Version 6.5.4.15.116n
- For SM9800, NSsp 12400, and NSsp 12800, version 6.5.2.8-2n is safe
- For Gen 7: Any SonicOS firmware version higher than 7.0.1-5035
Indicators of Compromise
No indicators of compromise (IoCs) are available currently.
Threat Landscape
Ransomware affiliates, including those behind Akira ransomware, have swiftly moved to exploit this vulnerability. By compromising SSLVPN user accounts, they gain initial access to networks, deploy ransomware, and demand significant ransoms. This method underscores the high value placed on such vulnerabilities by threat actors.
Threat Group
The cyber security landscape is facing an escalating threat as multiple ransomware gangs, including HelloKitty and FiveHands, have been exploiting security vulnerabilities in SonicWall devices to infiltrate corporate networks. Adding to this list, the Akira ransomware group has also started leveraging these SonicWall bugs to gain initial access to victims’ systems.
Further information













