CyberWire Daily
CyberWire Daily
N2K Networks
A firewall wake up call. [Research Saturday]
23 minutes Posted Jan 20, 2024 at 8:10 am.
0:00
23:01
Download MP3
Show notes

Jon Williams from Bishop Fox is sharing their research on "It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable." SonicWall published advisories for CVE-2022-22274 and CVE-2023-0656 a year apart after finding that NGFW series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities.

The research states "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern." They also found that when they scanned SonicWall firewalls with management interfaces exposed to the internet, they found that 76% are vulnerable to one or both issues.

The research can be found here:

Learn more about your ad choices. Visit megaphone.fm/adchoices