Jump to content

Dell patches gaping holes in its SonicWALL security software


sincity

Recommended Posts

Dell patches gaping holes in its SonicWALL security software

Dell has just patched some serious flaws in its security solutions used on business PCs.

The six vulnerabilities are in SonicWALL GMS and SonicWALL Analyzer and affect version 8.0 and 8.1 of these products respectively. They were found by security firm Digital Defense Incorporated, who brought them to Dell's attention, and noted that the PC vendor had been "extremely professional" when it came to resolving the flaws.

In an advisory provided with the hotfix issued, Dell stated: "Vulnerabilities were found pertaining to command injection, unauthorized XXE, default account, and unauthorized modification of virtual appliance networking information.

"To fix these vulnerabilities, Dell highly recommends that existing users of Dell SonicWALL GMS and Analyzer Hotfix 174525."

Password pickle

One of the vulnerabilities involves an easily guessed password for a hidden default account (which NSA conspiracy theorists have, predictably enough, been pleased to hear about) which when exploited could potentially give an attacker control over any device connected to the company network.

If you run the software in question, you should most definitely be addressing this issue right now.

Dell advises: "GMS/Analyzer/UMA Hotfix 174525 is available for download from https://www.mysonicwall.com.

"Users should log into MySonicWALL and click on Downloads > Download Center in the navigation panel on the left, then select GMS/Analyzer – Virtual Appliance or GMS/Analyzer – Windows in the Software Type drop down menu."

In other recent Dell news, the company advised that its PCs will be increasing in price to the tune of 10% thanks to the weakening of the pound against the dollar triggered by Brexit.

Via: Win Beta

TZe2ayZoBPA
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.