SonicWall has released updates to fix critical vulnerabilities affecting their firewalls and Email Security appliances, addressing issues that could lead to device crashes and unauthorized system access. These flaws include buffer overflow bugs in the SonicOS SSL VPN service and high-severity system file modification vulnerabilities in Email Security. #SonicOS #BufferOverflow #EmailSecurityVulnerabilities
Keypoints
- SonicWall rolled out security patches for multiple vulnerabilities affecting their firewalls and email security appliances.
- A buffer overflow flaw in SonicOS SSL VPN could allow remote, unauthenticated attackers to cause device crashes.
- The vulnerabilities are addressed in SonicOS versions 7.3.1-7013 and 8.0.2-8011, with some older models unaffected.
- Two significant security flaws in Email Security appliances could enable arbitrary code execution and directory traversal attacks.
- SonicWall recommends limiting SSL VPN access and updating systems to the latest firmware to mitigate risks.