Attackers exploited two critical zero-day vulnerabilities in SonicWall's SMA1000 remote access VPN appliances to gain full administrative control over target networks. The flaws, which allow authentication bypass, were chained to deploy custom malware implants for persistent access, according to a report from BleepingComputer.

The two vulnerabilities, tracked as CVE-2024-38474 and CVE-2024-38475, are authentication bypass flaws. When chained, they enable an unauthenticated attacker to take complete control of an affected SMA1000 appliance. These internet-facing VPN devices are typically deployed at the network perimeter, making this flaw extremely dangerous.

The campaign focused on stealth rather than disruption. Attackers installed custom, platform-specific malware to establish a persistent foothold in the compromised environment. The use of bespoke malware suggests a well-resourced operation with long-term, covert access as its goal, likely for intelligence gathering.

This attack highlights a growing trend: adversaries are increasingly targeting perimeter devices like VPN concentrators and firewalls. Compromising these appliances allows them to bypass internal defenses and operate from a trusted position within the network.

SonicWall has released patched firmware (version 12.4.1-02959 or later) to address the vulnerabilities. The company urges immediate patching. Organizations using SMA1000 devices should conduct forensic reviews to check for indicators of compromise, such as unexpected files or processes, to determine if they were affected during the zero-day window.

Beyond patching, this incident underscores the need for robust monitoring of perimeter devices and strong network segmentation to limit damage from breaches. The deployment of custom malware indicates that attackers are investing significant resources to maintain hidden access for as long as possible.


根據 BleepingComputer 的報告,攻擊者利用了 SonicWall SMA1000 遠端存取 VPN 設備中的兩個關鍵零日漏洞,以獲得對目標網絡的完整管理員控制權。這兩個漏洞允許進行驗證繞過,攻擊者將其鏈接使用,以部署定制惡意軟件植入程式,實現持久性存取。

這兩個漏洞被編號為 CVE-2024-38474 和 CVE-2024-38475,均屬於驗證繞過漏洞。當它們被鏈接利用時,可使未經驗證的攻擊者完全控制受影響的 SMA1000 設備。這些面向互聯網的 VPN 設備通常部署在企業網絡邊界,使得此漏洞極其危險。

此次攻擊行動側重於隱蔽性而非破壞。攻擊者安裝了定制的、針對特定平台的惡意軟件,旨在受侵入的環境中建立持久據點。使用定制惡意軟件表明,這是一個資源充足的行動,其目標是獲取長期、隱蔽的存取權限,很可能用於情報收集。

這起攻擊突顯了一個日益增長的趨勢:對手越來越多地針對像 VPN 集中器和防火牆這類邊界設備。入侵這些設備使他們能夠繞過內部防禦,並在受信任的網絡內部位置進行操作。

SonicWall 已發布修補韌體(版本 12.4.1-02959 或更高版本)以解決這些漏洞。該公司敦促立即進行修補。使用 SMA1000 設備的組織應進行法證審查,以檢查是否存在入侵指標,例如異常文件或進程,從而確定其是否在零日漏洞窗口期內受到影響。

除了修補之外,這起事件還突顯了對邊界設備進行強力監控以及實施強大網絡分段以限制入侵損害的必要性。定制惡意軟件的部署表明,攻擊者正投入大量資源,以在盡可能長的時間內維持隱藏存取。

新聞來源 / Original News Source