Lazarus aka Hidden Cobra APT Group – Active IOCs
July 22, 2024VMware ESXi Systems Targeted by New Play Ransomware Linux Variant – Active IOCs
July 22, 2024Lazarus aka Hidden Cobra APT Group – Active IOCs
July 22, 2024VMware ESXi Systems Targeted by New Play Ransomware Linux Variant – Active IOCs
July 22, 2024Severity
High
Analysis Summary
CVE-2024-40764 CVSS:7.5
SonicWall SonicOS is vulnerable to a denial of service, caused by a heap-based buffer overflow in the IPSec VPN. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
CVE-2024-29014 CVSS:7.1
SonicWall NetExtender Windows client could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an error when processing an EPC Client update. By using a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
- Denial of Service
- Code Execution
Indicators of Compromise
CVE
- CVE-2024-40764
- CVE-2024-29014
Affected Vendors
Affected Products
- SonicWall SonicOS 6.5.4.4-44v-21-2395
- SonicWall NetExtender Windows 10.2.339
Remediation
Refer to SonicWall Advisory or patch, upgrade or suggested workaround information.