Attackers Exploit Two SonicWall SMA 1000 Zero-Days

Two zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances, including a critical pre-authentication SSRF flaw, are being exploited in the wild.

Why it matters

These zero-days represent a severe security risk for organizations using SonicWall SMA 1000 VPNs, potentially allowing pre-authentication attacks that could bypass protections.

SOC impact

Monitor VPN appliance logs and network telemetry for suspicious SSRF activity, confirm the presence of affected SonicWall SMA 1000 devices, and review alerts related to unusual access attempts prior to authentication.

Recommended actions

  1. Identify deployed SonicWall SMA 1000 VPN appliances in the environment
  2. Review logs for signs of SSRF or other anomalous requests before authentication
  3. Assess whether attack attempts exploiting these zero-days are present
  4. Monitor network traffic for indicators linked to SonicWall SMA 1000 vulnerabilities
  5. Consult the original SonicWall advisory and The Hacker News report for updates

Executive Summary

SonicWall has disclosed two zero-day vulnerabilities affecting its SMA 1000 VPN appliances that are actively exploited in the wild. One of these flaws is a critical pre-authentication Server-Side Request Forgery (SSRF) vulnerability scoring a maximum severity rating of 10.0. Both were discovered through internal research and may be combinable in an attack chain. This development increases risk for organizations relying on these VPN solutions by enabling attackers to interact with internal systems without authentication. Immediate operational awareness and verification of impacted assets are essential to defend against potential exploitation.

SOC Impact

Monitor VPN appliance logs and network telemetry for suspicious SSRF activity, confirm the presence of affected SonicWall SMA 1000 devices, and review alerts related to unusual access attempts prior to authentication.

What SOC Teams Should Validate

  • Identify deployed SonicWall SMA 1000 VPN appliances in the environment
  • Review logs for signs of SSRF or other anomalous requests before authentication
  • Assess whether attack attempts exploiting these zero-days are present
  • Monitor network traffic for indicators linked to SonicWall SMA 1000 vulnerabilities
  • Consult the original SonicWall advisory and The Hacker News report for updates

Why It Matters

These zero-days represent a severe security risk for organizations using SonicWall SMA 1000 VPNs, potentially allowing pre-authentication attacks that could bypass protections.

Source