Rewterz
Rewterz Threat Alert – Play Ransomware Gang Leaks Data Stolen From City of Oakland
March 6, 2023
Rewterz
Rewterz Threat Advisory – CVE-2023-27290 – IBM Observability with Instana missing Vulnerability
March 6, 2023

Rewterz Threat Advisory – Multiple SonicWall SonicOS Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-0656 CVSS:7.5

SonicWall SonicOS is vulnerable to a denial of service, caused by a stack-based buffer overflow vulnerability in the web management interface. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.

CVE-2023-1101 CVSS:4.3

SonicWall SonicOS SSLVPN could allow a remote authenticated attacker to bypass security restrictions, caused by improper restriction of excessive MFA attempts. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass authentication using excessive MFA codes.

Impact

  • Denial of Service
  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2023-0656
  • CVE-2023-1101

Affected Vendors

Sonicwall

Affected Products

  • SonicWall NSa 2700 7.0.1-5095
  • SonicWall NSa 3700 7.0.1-5095
  • SonicWall NSa 4700 7.0.1-5095
  • SonicWall NSa 5700 7.0.1-5095

Remediation

Refer to SonicWall Security Advisory for patch, upgrade or suggested workaround information. 

CVE-2023-0656

CVE-2023-1101