Join the Conversation

To sign in, use your existing MySonicWall account. To create a free MySonicWall account click "Register".

Interesting articles on the exposure posed by the SSLVPN vulnerability in SonicWall firewalls

LarryLarry All-Knowing Sage ✭✭✭✭

Starting with Bleeping Computer:

https://www.bleepingcomputer.com/news/security/over-25-000-sonicwall-vpn-firewalls-exposed-to-critical-flaws/

And going directly to the source, the Bishop Fox article:

https://bishopfox.com/blog/state-sonicwall-exposure-firmware-decryption-unlocks-insights

These two are "offset" (and I use that term lightly) by the following puff-piece in CRN:

https://www.crn.com/news/security/2024/how-sonicwall-put-msps-in-a-good-position-amid-critical-vulnerability-threat

I'm going to leave my musings out of this discussion. I've already voiced my opinion on this issue in other threads.

But I am interested in knowing if any of you in the Community are aware of other partners or clients who have some of these "under-served" devices.

Category: Entry Level Firewalls
Reply

Comments

  • ArkwrightArkwright Community Legend ✭✭✭✭✭

    Great stuff, thanks for that, waiting for part 3!

  • TKWITSTKWITS Community Legend ✭✭✭✭✭

    "if any of you in the Community are aware of other partners or clients who have some of these "under-served" devices."

    While the 'if it ain't broke, don't fix it' mentality of most businesses still reigns, yes I am aware of a handful of these 'under-served' devices.

  • MariuszMariusz Enthusiast ✭✭
    edited January 1

    I read the articles with great interest.

    Does Fortinet, for example, also have similar problems?

  • BWCBWC Cybersecurity Overlord ✭✭✭

    Fortinet is way ahead in some areas, but the amount of CVEs Fortinet products are creating is way higher than with SonicWall. Maybe FTNT is a more profitable target, dunno.

    —Michael@BWC

  • ArkwrightArkwright Community Legend ✭✭✭✭✭

    A simple "count" of CVEs is not a fair comparison across vendors. "CVEs per <something>" would be fair, but the problem here is defining "<something>". Even if you compare just the UTM platforms from different vendors [rather than simply the entirety of their portfolio], if they do different things then the one that does more should be "allowed" more CVEs. I think it's basically impossible to do fairly :)

  • JackBurtonJackBurton Newbie ✭

    Good Article, thanks

Sign In or Register to comment.