Full Report
A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.
Analysis Summary
# Vulnerability: SonicWall SonicOS Improper Access Control (Akira Ransomware Campaign)
## CVE Details
- **CVE ID:** CVE-2024-40766
- **CVSS Score:** 9.3 (Critical)
- **CWE:** CWE-284 (Improper Access Control)
## Affected Systems
- **Products:** SonicWall Gen 5, Gen 6, and Gen 7 Firewalls.
- **Versions:**
- SonicOS 7.0.1-5035 and older versions.
- SonicOS 6.5.4.15-116n and older versions.
- **Configurations:** Systems running SSL VPN services and/or Management Access. Specific risk noted for Gen 7 devices where configurations were migrated from Gen 6 without subsequent password resets.
## Vulnerability Description
CVE-2024-40766 is an improper access control flaw in the SonicOS management interface and SSL VPN. Under specific conditions, this vulnerability allows unauthorized users to gain resource access and can potentially cause the firewall to crash. In the context of recent attacks, it has been leveraged to bypass multi-factor authentication (MFA) and gain initial access to corporate networks.
## Exploitation
- **Status:** Exploited in the wild (Actively used by Akira Ransomware affiliates).
- **Complexity:** Low.
- **Attack Vector:** Network (Remote).
## Impact
- **Confidentiality:** High (Unauthorized access to internal resources).
- **Integrity:** High (Potential for unauthorized configuration changes and lateral movement).
- **Availability:** High (Firewall crashes and subsequent ransomware deployment).
## Remediation
### Patches
- **Gen 7:** Update firmware to **version 7.3.0** or higher.
- **Gen 6:** Update to version **6.5.4.15-117n** or higher.
- **Gen 5:** Note that Gen 5 is End-of-Life; upgrade to supported hardware is recommended.
### Workarounds
- **Credential Rotation:** Immediately reset all local user account passwords, especially for accounts with SSL VPN access.
- **MFA:** Ensure MFA is enforced for all accounts, though note that this specific flaw may bypass some implementations if credentials are compromised.
- **Access Control:** Restrict management access to trusted IP addresses only.
- **Disable Service:** If not mission-critical, disable the SSL VPN service entirely until patched.
## Detection
- **Indicators of Compromise (IoCs):**
- Presence of `rwdrv.sys` and `hlpdrv.sys` in `C:\Users\<USER>\AppData\Local\Temp\2\` (BYOVD attack signatures).
- Execution of `powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject"` to delete backups.
- Use of the `-dellog` argument in Akira ransomware executables to clear Windows event logs.
- **Detection Methods:** Monitor for unusual login activity from SonicWall VPN IPs followed by immediate pivot attempts to Domain Controllers (often within hours).
## References
- **SonicWall Advisory:** hxxps[://]www[.]sonicwall[.]com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430
- **NVD Entry:** hxxps[://]nvd[.]nist[.]gov/vuln/detail/cve-2024-40766
- **Huntress Analysis:** hxxps[://]www[.]huntress[.]com/blog/exploitation-of-sonicwall-vpn