SonicWall Releases Security Update
Security updates for SonicWall products address two vulnerabilities rated as Critical and two rated as High
Summary
Security updates for SonicWall products address two vulnerabilities rated as Critical and two rated as High
Affected platforms
The following platforms are known to be affected:
The following platforms are also known to be affected:
- SonicWall Global Management System (GMS)- 9.3.1-SP2-Hotfix1 and earlier versions
- SonicWall Analytics - 2.5.0.3-2520 and earlier versions
- SonicWall Switch version 1.1.1.0-2s and earlier versions
- SonicWall Hosted Email Security 10.0.17.7319 and earlier versions
- SonicWall Network Security Manager (NSM)
- SonicWall Capture Security Appliance
- SonicWall Capture Client
- SonicWall Email Security 10.0.17 and earlier versions are using OpenSSL 1.1.1n
- SonicWall NetExtender Client
- SonicWall Connect Tunnel Client
- SonicWave Access Points
Threat details
Introduction
SonicWall has released security advisories to address vulnerabilities in multiple products, with two vulnerabilities rated as Critical and two vulnerabilities rated as High. The critical vulnerabilities address an unauthenticated SQL injection in SonicWall GMS and Analytics and an arbitrary code execution.
An unauthenticated remote attacker, could exploit some of these vulnerabilities to take control of a system.
Remediation advice
Affected organisations are encouraged to review the SonicWall security advisories and apply the necessary updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
SNWLID-2022-0007 - Unauthenticated SQL Injection in SonicWall GMS and Analytics https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0007 |
| Patch |
SNWLID-2022-0011 - OpenSSL c_rehash script allows command injection CVE-2022-1292 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011 |
| Patch |
SNWLID-2022-0013 - SonicWall Switch Post-Authenticated Remote Code Execution https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0013 |
| Patch |
SNWLID-2022-0014 - SonicWall Hosted Email Security Capture ATP Bypass https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0014 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 25 July 2022 2:24 pm