UPDATE: SonicWall has now released what it calls "a critical firmware update" to patch the zero-day vulnerability detected on SMA 100 series 10.x code.
"All SonicWall customers with active SMA 100 series devices running 10.x code should immediately apply the patch on physical and virtual appliances," the company said in a statement. "The patch also contains additional code to strengthen the device."
"As previously stated, SonicWall firewalls and SMA 1000 series appliances, as well as all respective VPN clients, are unaffected and remain safe to use. No action for these products is required."
Security firm the NCC Group believes that it has identified an active exploit involving a zero-day SonicWall vulnerability that was disclosed last week (opens in new tab). The company has not revealed exact details regarding the exploit as that might enable further attacks to be launched.
“Per the SonicWall advisory… we've identified and demonstrated exploitability of a possible candidate for the vulnerability described and sent details to SonicWall - we've also seen indication of indiscriminate use of an exploit in the wild - check logs,” NCC explained in a tweet (opens in new tab).
SonicWall has not confirmed whether the exploit discovered by NCC researchers involves one of the vulnerabilities disclosed last week. Until more information is revealed, NCC has advised that owners of the vulnerable SonicWall devices cited in the firm’s recent security advisory should restrict the IP addresses that are allowed to access the management interface to only those associated with authorized personnel.
- We've highlighted the best antivirus (opens in new tab) solutions around
- Check out our roundup of the best firewalls (opens in new tab)
- We've also assembled a list of the best endpoint protection (opens in new tab) tools
SonicWall recently warned customers that a zero-day vulnerability had been found affecting several of its VPN products. Following further investigation, however, the number of affected devices was significantly reduced.
Nevertheless, SonicWall admitted to the unconfirmed presence of a zero-day vulnerability affecting its SMA 100 Series – a range of networking devices used to provide access to internal networks for remote employees – something that has become increasingly needed with COVID-19 restrictions still in place for many businesses.
SonicWall is continuing to investigate (opens in new tab) potential vulnerabilities and reminded users of the importance of installing the latest security updates in order to guarantee protection against cybersecurity threats. The firm added that many of the proof of concept exploits being shared are not possible if patches released in 2015 are installed.
- Also, here's our list of the best routers (opens in new tab) for your business
Via ZDNet (opens in new tab)