SonicWall next-generation firewall (NGFW) devices [2] [3] [6] [7] [8], specifically series 6 and 7, have been found to have exposed online management interfaces, posing a significant security risk [7]. These devices are vulnerable to denial-of-service (DoS) attacks and potential remote code execution (RCE) [1] [2] [7].


Two DoS security flaws [2] [7], known as CVE-2022-22274 and CVE-2023-0656 [2] [3] [6] [7] [8], have been identified as the main vulnerabilities [7]. Research conducted by Bishop Fox and WatchTowr Labs revealed that over 178,000 SonicWall firewalls with exposed management interfaces are vulnerable to these issues. They found that 76% of the devices were vulnerable to at least one of the bugs [1], while 62% were vulnerable to both [1].

The impact of a widespread DoS attack could be severe [1] [8], as the devices require administrative action to restore normal functionality after three crashes [1]. While remote code execution is possible [1], it is currently considered unlikely due to the challenges involved in exploiting the vulnerabilities [1].

To mitigate the risk of a DoS attack [6], network administrators are urged to check for vulnerable devices and update to the latest firmware [6], which provides protection against both vulnerabilities. It is also recommended to ensure that the management interface is not exposed to the internet to further mitigate these threats [5]. This is particularly important considering SonicWall’s large customer base, which includes government agencies and global enterprises [7].

The vulnerabilities were discovered by Bishop Fox security experts, and exploitation is possible if attackers know the firmware running on the SonicWall firewall [4]. However, a patch is already available to address these vulnerabilities, making it crucial for network administrators to promptly update their devices.


