SonicWall is urging users of its Secure Mobile Access 100 series and remote access products to immediately apply patches. A majority of the devices are affected by eight critical-to-medium-severity vulnerabilities even after enabling their web application firewall, a SonicWall security advisory says. The U.S. Cybersecurity and Infrastructure Security Agency has also released an advisory encouraging users and administrators using the SonicWall SMA 100 series appliances to apply the necessary firmware updates at the earliest opportunity. The most severe of these flaws are a set of unauthenticated heap- and stack-based buffer overflow vulnerabilities, says Tenable’s Claire Tills.”]
Source: https://www.govinfosecurity.com/sonicwall-sma-100-series-users-urged-to-apply-latest-fix-a-18089