Vulnerabilities

180k Internet-Exposed SonicWall Firewalls Vulnerable to DoS Attacks, Possibly RCE

Two DoS vulnerabilities patched in 2022 and 2023 haunt nearly 180,000 internet-exposed SonicWall firewalls.

Two DoS vulnerabilities patched in 2022 and 2023 haunt nearly 180,000 internet-exposed SonicWall firewalls.

The majority of internet-exposed SonicWall next-generation firewall series 6 and 7 devices have not been patched against two potentially serious vulnerabilities, cybersecurity firm Bishop Fox reports.

The issues, tracked as CVE-2022-22274 and CVE-2023-0656 and rated critical- and high-severity, respectively, can be exploited remotely, without authentication. An attacker can use them to cause a denial-of-service (DoS) condition, but remote code execution (RCE) has not been ruled out either. SonicWall released patches for them in March 2022 and March 2023.

According to Bishop Fox, the two flaws are essentially the same, “but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern.”

Scanning the internet for vulnerable devices, the cybersecurity firm discovered that more than 178,000 of the SonicWall firewalls that have a publicly accessible web management interface are vulnerable to at least one of the security defects.

“The impact of a widespread attack could be severe. In its default configuration, SonicOS restarts after a crash, but after three crashes in a short period of time it boots into maintenance mode and requires administrative action to restore normal functionality,” Bishop Fox notes.

In its advisories, SonicWall notes that it is not aware of active exploitation of any of these vulnerabilities and that it has received no reports of proof-of-concept (PoC) exploit code being published for them.

Advertisement. Scroll to continue reading.

However, PoC code targeting CVE-2023-0656 has been public since April 2023, when SSD Labs published it along with technical details on the bug.

By analyzing the root cause of these vulnerabilities, Bishop Fox identified a link between them and was able to create new PoC exploits for both. The exploit for CVE-2023-0656, the firm says, is similar to what SSD Labs published almost a year ago.

“To our knowledge, no previous research has been published establishing a link between CVE-2022-22274 and CVE-2023-0656. Clearly, both vulnerabilities share the same underlying bug, but the initial patch only fixed the vulnerable code in one place, leaving the other instances to be found and reported a year later,” BishopFox says.

After developing the PoCs, the cybersecurity firm started looking for vulnerable devices accessible from the internet, and discovered that more than 146,000 firewalls remain unpatched against CVE-2022-22274, and that 178,000 are not patched against CVE-2023-0656.

In fact, almost all 146,000 vulnerable SonicWall firewalls are missing patches for both vulnerabilities. With CVE-2022-22274 also exploitable for remote code execution (RCE), these devices are potentially at risk of more than just DoS.

SonicWall customers are advised to apply the available patches as soon as possible. Vulnerabilities in SonicWall firewalls are known to have been exploited in malicious attacks.

Related: Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities

Related: SonicWall Patches Critical Vulnerabilities in GMS, Analytics Products

Related: Custom Chinese Malware Found on SonicWall Appliance

Related Content

Vulnerabilities

The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls.

Vulnerabilities

The bugs could allow attackers to modify protected resources and escalate their privileges to administrator.

Vulnerabilities

The medium-severity flaw has been exploited in combination with a critical bug for remote code execution.

Vulnerabilities

The vulnerabilities could be exploited to cause a denial-of-service (DoS) condition, execute arbitrary code, or access arbitrary files and directories.

Nation-State

The threat actor stole the firewall configuration files of all SonicWall customers who used the cloud backup service.

Malware & Threats

Threat actors have rapidly compromised more than 100 SonicWall SSL VPN accounts pertaining to over a dozen entities.

Network Security

In early September, hackers stole the firewall configuration backup files stored using the MySonicWall service.

Ransomware

In one attack, the hackers leveraged the Datto RMM utility on a domain controller and various other legitimate tools to evade detection.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version