Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > rocksolid.shared.security > #36 > unrolled thread

Do you use the Sonic firewall ?

Started byAnonymous <poster@anon.com>
First post2020-10-16 03:11 -0700
Last post2020-10-17 08:42 -0700
Articles 3 — 2 participants

Back to article view | Back to rocksolid.shared.security


Contents

  Do you use the Sonic firewall ? Anonymous <poster@anon.com> - 2020-10-16 03:11 -0700
    Re: Do you use the Sonic firewall ? AnonUser@rslight.i2p (AnonUser) - 2020-10-17 01:37 +0000
    Well... Anonymous <poster@anon.com> - 2020-10-17 08:42 -0700

#36 — Do you use the Sonic firewall ?

FromAnonymous <poster@anon.com>
Date2020-10-16 03:11 -0700
SubjectDo you use the Sonic firewall ?
Message-ID<opsec.734.39emly@anon.com>
Time for an update, this thing is reaaally wide open:

https://de.tenable.com/blog/cve-2020-5135-critical-sonicwall-vpn-portal-stack-based-buffer-overflow-vulnerability

-- 
Posted on def2

[toc] | [next] | [standalone]


#37

FromAnonUser@rslight.i2p (AnonUser)
Date2020-10-17 01:37 +0000
Message-ID<8a3ff00b1280ce87ce8419cc75a403fa$1@www.novabbs.com>
In reply to#36
Anonymous wrote:

> Time for an update, this thing is reaaally wide open:

> https://de.tenable.com/blog/cve-2020-5135-critical-sonicwall-vpn-portal-stack-based-buffer-overflow-vulnerability

Looks like they believe they've patched them all

"SonicWall published patches for all 11 vulnerabilities."

Affected Versions 	Fixed Versions
SonicOS 6.5.4.7-79n and below 	SonicOS 6.5.4.7-83n
SonicOS 6.5.1.11 and below 	SonicOS 6.5.1.12-1n
SonicOS 6.0.5.3-93o and below 	SonicOS 6.0.5.3-94o
SonicOSv 6.5.4.4-44v-21-794 and below 	SonicOS 6.5.4.v-21s-987
SonicOS 7.0.0.0-1 	SonicOS 7.0.0.0-2 and above

-- 
Posted on: novaBBS
www.novabbs.com

[toc] | [prev] | [next] | [standalone]


#38 — Well...

FromAnonymous <poster@anon.com>
Date2020-10-17 08:42 -0700
SubjectWell...
Message-ID<opsec.736.1thgt3@anon.com>
In reply to#36
>Looks like they believe they've patched them all

like the song says:
"that don't impress me much". as a firewall, you have one fucking job, which is to keep the bad guys out. if you prove you cannot do it and instead allow remote code execution, you have not only failed in the sense that you did _not_ keep the bad guys out, but in fact you invited them in and opened the door.

-- 
Posted on def2

[toc] | [prev] | [standalone]


Back to top | Article view | rocksolid.shared.security


csiph-web