Sonicwall Network Security Manager Remote Code Execution Scanner
Targets the Apache Log4j JNDI endpoint in Sonicwall NSM, allowing attackers to execute arbitrary commands remotely.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
24 days 17 hours
Scan only one
Domain, IPv4, Subdomain
Toolbox
Sonicwall Network Security Manager (NSM) is a centralized management platform used by IT security professionals, managed service providers, and network administrators to oversee Sonicwall security appliances. It simplifies firewall operations, enhances security visibility, and ensures consistent policy enforcement across large, distributed networks. The software reduces administrative overhead by enabling rapid deployment of updates and policies, while also helping organizations maintain compliance with security standards.
The Remote Code Execution (RCE) vulnerability in Sonicwall NSM arises from the exploitation of Apache Log4j's JNDI features. This flaw allows attackers to inject malicious JNDI lookups that trigger arbitrary code execution on the server. The vulnerability is severe due to the widespread use of Log4j in Java applications, and it can be exploited without authentication in many cases.
Specifically, the vulnerability targets the Log4j logging component within Sonicwall NSM's web interface. Attackers can send crafted requests containing malicious JNDI strings to endpoints that process user input, such as login forms or API calls. The Log4j library then processes these strings, leading to remote code execution on the NSM server.
If exploited, an attacker can gain full control over the Sonicwall NSM server, potentially compromising all managed Sonicwall appliances. This could lead to data breaches, network disruption, and unauthorized access to sensitive network configurations. The CVSS score of 10.0 underscores the critical nature of this vulnerability, requiring immediate remediation.