Site Archives Sonicwall

SonicWALL SSL-VPN 200 Patch Released

Posted on June 2nd, 2009

GSA Reference Number: AD090602-01

Simply Put: SonicWALL has released a patch for an internal memory disclosure vulnerability in its SSL-VPN products.  Note, this is not a vulnerability with its firewall or unified threat management products, just the stand-alone SSL VPN devices.  The vulnerability allows an unauthenticated attacker to manipulate the portal login page to read parts of internal memory.  This vulnerability could lead to information disclosure.

SonicWALL Licensing Server Failure

Posted on December 4th, 2008

Tuesday morning December 2nd one of SonicWALL’s Licensing Servers failed to respond correctly to licensing queries from SonicWALL Firewalls.  Although this issue has been corrected, it left some SonicWALLs with reduced functionality.  SonicWALL devices will disable all licensed content if they are unable to contact a SonicWALL server.

SonicWALL Content Filter Security Vulnerability

Posted on October 31st, 2008

GSA Reference Number: AD081031-01
Updated: 11-3-2008

Simply Put: SonicWALL has released an advisory regarding a new vulnerability found in its content filter.  If a user behind a SonicWALL with content filtering enabled clicks on a malicious link, an attacker can cause malicious javascript to be executed through the content filter’s “Blocked Traffic” screen.  This vulnerability only affects SonicWALLs running the Enhanced OS using the content filter with the CFS Block Page.  See below for vulnerable versions.

Sonicwall VPN Client Advisory

Posted on December 11th, 2007

GSA Reference Number: AD071211-01

Simply Put: A notice has been sent out on a vulnerability in the SonicWALL Global VPN Client. This client is used on computers outside the organization, such as home PCs and laptops, to connect back to the corporate network. This is not a vulnerability affecting the firewall. If a user downloads a new configuration file it could be used to run arbitrary code on the machine. This file would have to be downloaded from a malicious website or received in an email from an attacker. The likelihood a user would download this type of file is low, but not impossible. Gladiator recommends installing the new version of the application on each laptop or home PC needing VPN access. This product only affects users with SonicWALL Firewalls. See below for technical details.