CyberWire Daily

A firewall wake up call. [Research Saturday]

01.20.2024 - By N2K NetworksPlay

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

Jon Williams from Bishop Fox is sharing their research on "It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable." SonicWall published advisories for CVE-2022-22274 and CVE-2023-0656 a year apart after finding that NGFW series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities.

The research states "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern." They also found that when they scanned SonicWall firewalls with management interfaces exposed to the internet, they found that 76% are vulnerable to one or both issues.

The research can be found here:

It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable

More episodes from CyberWire Daily