Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix
ID: 31ce082a-c464-5de9-a3ff-285c3ce74436
STIX ID: report--31ce082a-c464-5de9-a3ff-285c3ce74436
Feed Name: Security Affairs
ReliaQuest observed active exploitation of SonicWall CVE-2024-12802 on Gen6 SSL-VPN appliances where firmware updates alone are insufficient: six manual LDAP reconfiguration steps are required to prevent an MFA bypass that lets attackers authenticate via UPN while MFA is enforced on SAM. Attackers brute-forced VPN accounts, bypassed MFA, moved quickly to file servers (sometimes within 30 minutes), attempted Cobalt Strike deployment and driver-based EDR disabling, and left log signals such as sess="CLI" and Event IDs 238/1080; Gen6 devices are end-of-life so migration to supported hardware is recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
