meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

A firewall wake up call. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

Tech News, News, Daily News, Technology

4.81.1K Ratings

🗓️ 20 January 2024

⏱️ 21 minutes

🧾️ Download transcript

Summary

Jon Williams from Bishop Fox is sharing their research on "It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable." SonicWall published advisories for CVE-2022-22274 and CVE-2023-0656 a year apart after finding that NGFW series 6 and 7 devices are affected by two unauthenticated denial-of-service vulnerabilities. The research states "Our research found that the two issues are fundamentally the same but exploitable at different HTTP URI paths due to reuse of a vulnerable code pattern." They also found that when they scanned SonicWall firewalls with management interfaces exposed to the internet, they found that 76% are vulnerable to one or both issues. The research can be found here: It’s 2024 and Over 178,000 SonicWall Firewalls are Publicly Exploitable Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the CyberWire Network, powered by N2K.

0:07.0

Today's episode is sponsored by SRM, your first call for cybersecurity and

0:18.1

investigations. Threats today are evolving faster than ever before and since 2005 SRM has pioneered

0:25.3

tailored security solutions for global corporations and their executives.

0:29.5

Whether it's defending against cyber attacks with their award-winning team of ethical hackers and incident response specialists,

0:36.4

or navigating the murky waters of compliance and ESG challenges,

0:40.9

SRMs, Insight and Straight straightforward advice will help you navigate complex risks

0:46.4

and emerge more resilient.

0:48.4

Their secret, a culture that nurtures the sharpest minds, giving them access to the newest technologies and the freedom

0:55.3

to solve problems in new ways, enabling them to craft simple effective solutions for your

1:01.4

unique cyber challenges.

1:03.7

Search your first call to discover how SRM can help your business. Hello everyone and welcome to the CyberWire's research Saturday.

1:27.0

I'm Dave Bitner and this is our weekly conversation with researchers and analysts tracking

1:32.2

down the threats and vulnerabilities,

1:34.3

solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace.

1:40.2

Thanks for joining us.

1:55.0

We're diving into this because we are interested in getting more familiar with the Sonic Wall Next Generation Firewall Platform, Sonic OS. It's been the subject of a lot of vulnerabilities in the past and we wanted to be prepared

2:00.2

to be able to research in the platform whenever anything new came out.

2:05.0

That's John Williams, senior security engineer at Bishop Fox.

2:09.0

The research we're discussing today is titled Sonic Wall Firewalls are publicly exploitable. And so in order to do that I went back and looked through the history of all the different

2:26.3

advisories that had been released looking for things that were

2:30.1

unauthenticated, had a potential for remote code execution,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.