Web_Logo
Remote Support
Security Alert: SonicWall Remote Access Flaws Exploited
Home » Security Alerts  »  Security Alert: SonicWall Remote Access Flaws Exploited

Security Alert: SonicWall Remote Access Flaws Exploited

The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that two vulnerabilities in SonicWall's SMA1000 range of remote access devices are being actively exploited by attackers.

  • What it is: Two flaws, a server-side request forgery bug and a code injection bug, in the SMA1000 appliance that many businesses use to give staff secure remote access to internal systems.
  • Who is affected: Any business running a SonicWall SMA1000 device, particularly those used for VPN or remote access.
  • The risk: Attackers exploiting these flaws can potentially bypass security controls and gain unauthorised access to internal networks.
  • What to do: Apply SonicWall's latest firmware update as soon as possible, and review remote access logs for unusual activity.

If you are unsure whether your business uses an affected device, we recommend checking with your IT provider before assuming you are not exposed. Full details are available in the CISA advisory.