SonicWall Security Updates – 04 October 2023

SonicWall has released security updates to fix multiple vulnerabilities in NetExtender Windows (32 and 64-bit) 10.2.336 and earlier versions.

The addressed vulnerabilities could allow the attacker to gain elevated privileges on affected systems by sending a specially crafted request.

The addressed vulnerabilities:

1. SonicWall NetExtender Pre-Logon Vulnerability (CVE-2023-44218):

  • CVSS: 8.8
  • Attack Vector: Adjacent
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

2. SonicWall Net Extender Local Privilege Escalation Vulnerability (CVE-2023-44217):

  • CVSS: 7.9
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Gain Privileges
Vulnerabilities
  • CVE-2023-44217
  • CVE-2023-44218
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SonicWall Security Advisory

References