THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Tuesday, July 13, 2021
Attackers have the potential to wreak havoc on an organization's business processes.
FREMONT, CA: Positive Technologies provides additional information about a vulnerability discovered by its researcher, Nikita Abramov, enabling authenticated attackers to take complete control of the on-premises SonicWall Network Security Manager (NSM). NSM is designed to centralize SonicWall firewalls’ management and monitor network traffic for threats and risks. SonicWall is ranked fifth in the world by IDC among manufacturers of hardware security tools.
CVE-2021-20026, also known as CVE-2021-20026, is a critical vulnerability with a CVSSv3 score of 8.8. To exploit the vulnerability, an attacker must be logged in as a SonicWall NSM user. Once logged in, the attacker can inject OS commands into a user request, granting them access to all features of the vulnerable on-premises SonicWall NSM platform and the underlying operating system. SonicWall patched this vulnerability in May 2021.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Nikita Abramov, Positive Technologies researcher, explains, “A successful attack on a vulnerable device requires authorization in NSM with a minimum level of privileges. SonicWall NSM allows centralized management of hundreds of devices. Tampering with this system may negatively impact a company's ability to work, to the point of full disruption of its protection system and stopping of business processes. As with Cisco ASA, successful attackers could disable access to the company's internal network by blocking VPN connections, or write new network traffic policies thus fully preventing its checks by a firewall.”
SonicWall PSIRT adds, “Through ongoing collaboration with Positive Technologies, SonicWall validated and patched a post-authentication vulnerability within the on-premises version of the Network Security Manager (NSM) service. This vulnerability only impacts on-premises deployments and not the more common SaaS version of the NSM service. Impacted SonicWall partners and customers were quickly informed of the patch and were provided upgrade guidance in May 2021.”
Technically, this vulnerability is caused by insufficient data filtering and direct transmission to an operating system for processing. Such errors can be reduced or eliminated by implementing secure coding practices, which decreases the likelihood that coding weaknesses will survive the development lifecycle. However, because code flaws can and do slip past automated code checks, enabling penetration testing of devices before their release into production can provide increased assurance that specific flaws and vulnerabilities are discovered and addressed.
Automating the detection and prioritization of such vulnerabilities is possible with vulnerability management systems such as MaxPatrol VM. To detect signs of penetration (for example, if an update cannot be installed), leverage SIEM solutions (specifically, MaxPatrol SIEM), which assist in identifying suspicious server behavior, logging an incident, and preventing intruders from moving laterally within the corporate network promptly.
More in News