Skip to main content

SonicWall Releases Security Update

Security updates for SonicWall products address two vulnerabilities rated as Critical and two rated as High

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates for SonicWall products address two vulnerabilities rated as Critical and two rated as High


The following platforms are also known to be affected:

  • SonicWall Global Management System (GMS)-  9.3.1-SP2-Hotfix1 and earlier versions
  • SonicWall Analytics -  2.5.0.3-2520 and earlier versions
  • SonicWall Switch version 1.1.1.0-2s and earlier versions
  • SonicWall Hosted Email Security 10.0.17.7319 and earlier versions
  • SonicWall Network Security Manager (NSM)
  • SonicWall Capture Security Appliance
  • SonicWall Capture Client
  • SonicWall Email Security 10.0.17 and earlier versions are using OpenSSL 1.1.1n
  • SonicWall NetExtender Client
  • SonicWall Connect Tunnel Client
  • SonicWave Access Points

Threat details

Introduction

SonicWall has released security advisories to address vulnerabilities in multiple products, with two vulnerabilities rated as Critical and two vulnerabilities rated as High. The critical vulnerabilities address an unauthenticated SQL injection in SonicWall GMS and Analytics and an arbitrary code execution.

An unauthenticated remote attacker, could exploit some of these vulnerabilities to take control of a system.


Remediation advice

Affected organisations are encouraged to review the SonicWall security advisories and apply the necessary updates.


Remediation steps

Type Step
Patch

SNWLID-2022-0007 - Unauthenticated SQL Injection in SonicWall GMS and Analytics 


https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0007
Patch

SNWLID-2022-0011 - OpenSSL c_rehash script allows command injection CVE-2022-1292


https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011
Patch

SNWLID-2022-0013 - SonicWall Switch Post-Authenticated Remote Code Execution


https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0013
Patch

SNWLID-2022-0014 - SonicWall Hosted Email Security Capture ATP Bypass


https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0014

Definitive source of threat updates


Last edited: 25 July 2022 2:24 pm