Site Archives

Sonicwall VPN Client Advisory

Posted on December 11th, 2007

GSA Reference Number: AD071211-01

Simply Put: A notice has been sent out on a vulnerability in the SonicWALL Global VPN Client. This client is used on computers outside the organization, such as home PCs and laptops, to connect back to the corporate network. This is not a vulnerability affecting the firewall. If a user downloads a new configuration file it could be used to run arbitrary code on the machine. This file would have to be downloaded from a malicious website or received in an email from an attacker. The likelihood a user would download this type of file is low, but not impossible. Gladiator recommends installing the new version of the application on each laptop or home PC needing VPN access. This product only affects users with SonicWALL Firewalls. See below for technical details.