- Product
Product Overview
Sophisticated security with unmatched simplicityCloud SIEM
Pre-configured detections across your environmentHoneypots
Deception technology to detect lateral movementEndpoint Visibility
Real-time monitoring with added detection & responseSecurity Reports
Data visualizations, compliance reports, and executive summariesAutomated Response
Detect, prioritize, and neutralize threats around the clockIntegrations
Cloud, on-prem, and open API connectionsXDR Platform
A complete view to identify risk, and things operational
- Pricing
- Why Blumira
Why Blumira
The Security Operations platform IT teams loveWatch A Demo
See Blumira in action and how it builds operational resilienceUse Cases
A unified security solution for every challengePricing
Unlimited data and predictable pricing structureCompany
Our human-centered approach to cybersecurityCompare Blumira
Find out how Blumira stacks up to similar security toolsIntegrations
Cloud, on-prem, and open API connectionsCustomer Stories
Learn how others like you found success with Blumira
- Solutions
- Partners
- Resources
As of late Friday morning, SonicWall was in the early stages of advising its customers of a breach which may have impacted its security products. While initial reports indicated a wide range of potentially impacted products across the SonicWall product line, this was later clarified to just the SMA (Secure Mobile Access) 100. The SMA 100 is an appliance which is intended to provide secure access to data center, cloud, and SaaS (software as a service) resources from a single portal.
The announcement came four days after proof of concept (POC) exploit code for CVE-2020-5144 was released, which describes exploitation of the SonicWall Global VPN Windows client for privilege escalation by leveraging a vulnerability that allowed the executable search order to be hijacked. This would allow an ordinary user to elevate their permissions to SYSTEM (administrative-level privileges).
Early this Monday morning, Darren Martyn, a security researcher, released a previously unpublished exploit against SonicWall SSL-VPN (which includes the firewall line). This particular method of exploitation was leveraged during the Hacking Team data breach and allowed the threat actor in that instance to not simply gain remote access to the device, but also add code to the login page to capture usernames and passwords.
What Should I Do if I’m a SonicWall Customer?
- Review security notices from SonicWall for the SMA 100, Global VPN client, and other SonicWall products.
- Apply security patches as they become available.
- Enable multi-factor authentication on any public-facing SonicWall VPN appliance.
- Enable multi-factor authentication on your mySonicWall.com support account.
- Configure all Internet traffic and management audit logs to be stored in a SIEM, analyzed and monitored for anomalous activity (like Blumira’s cloud SIEM that offers automated detection & response).
- Configure alerting on abnormalities and initiate your incident response plan if abnormalities are identified.
Erica Mixon
Erica is an award-winning writer, editor and journalist with over ten years of experience in the digital publishing industry. She holds a Bachelor’s degree in writing, literature and publishing from Emerson College. Her foray into technology began at TechTarget, where she provided editorial coverage on a wide variety...
More from the blog
View All Posts
Security Trends and Info
9 min read
| July 24, 2025
Critical Microsoft SharePoint Server vulnerability allows unauthorized code execution
Read More
Security Alerts
6 min read
| July 1, 2024
New Unauthenticated Remote Code Execution Flaw Identified in OpenSSH Server
Read More
Security Alerts
5 min read
| April 12, 2024
CVE-2024-3400: Palo Alto Vulnerabilities in GlobalProtect Gateway Lead to RCE
Read MoreSubscribe to email updates
Stay up-to-date on what's happening at this blog and get additional content about the benefits of subscribing.