A firewall wake up call. [Research Saturday]

Published: Jan. 20, 2024, 8:10 a.m.

Jon Williams from Bishop Fox is sharing their research on "It\u2019s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable." SonicWall published advisories for\xa0CVE-2022-22274\xa0and\xa0CVE-2023-0656\xa0a year apart after finding that NGFW series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities.\nThe research states "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern." They also found that when they scanned SonicWall firewalls with management interfaces exposed to the internet, they found that 76% are vulnerable to one or both issues.\nThe research can be found here:\nIt\u2019s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable\n\nLearn more about your ad choices. Visit megaphone.fm/adchoices