Skip to main content
Are SonicWall SSLVPN Devices Compromised in the Breach? - KH2370

Frequently Asked Questions

Are SonicWall SSLVPN Devices Compromised in the Breach?
 

Yes, recent investigations suggest that multiple SonicWall SSLVPN devices were compromised in the wake of the SonicWall data breach. Researchers have observed that attackers are using stolen VPN credentials and pre-shared keys (PSKs) obtained from the leaked cloud backup files to gain unauthorized access to SSLVPN gateways. This allows them to connect directly to corporate networks, bypassing standard user authentication in some cases.

The breach serves as a critical reminder for IT administrators to take immediate action. All organizations using SonicWall SSLVPN devices should assume that their credentials may have been exposed and perform a full credential rotation. This includes updating VPN passwords and PSKs, reviewing access logs for suspicious connections, and verifying firmware is up to date with the latest security patches.

To reduce ongoing risk and ensure your setup follows best practices, review the Secure configuration checklist and follow the steps to harden your SonicWall SSLVPN configuration against further compromise.

Privacy Settings / Datenschutz-Einstellungen