Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability identified in SonicWall's Network Security Manager (NSM) On-Prem software. The issue involves improper handling of uploaded archives, which could allow unauthorized file extraction outside of designated areas. This type of vulnerability, known as Zip Slip, poses a significant risk as it may enable malicious actors to overwrite or access critical system files. The main concern is confirming if your deployed NSM instances are potentially exposed and what the scope of impact might be.
- Malicious archives can overwrite critical files.
- Essential to confirm if NSM is exposed.
- Assess and address potential security risks.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by uploading a malicious archive file to the SonicWall Network Security Manager (NSM) On-Prem. This specially crafted archive, when processed by the NSM's file upload and archive handling, could allow the attacker to place files in unintended locations on the system. This capability, if leveraged effectively, could lead to significant compromise of the affected system.
- Requires authenticated access to upload files.
- Triggered by processing a crafted archive.
- Risk of unauthorized file access or modification.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to overwrite or replace system files when processing a crafted archive through the SonicWall Network Security Manager's file upload functionality. This could potentially impact the integrity and availability of the management service itself.
- System file integrity.
- Malicious archive upload.
- Service disruption or compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
This Zip Slip vulnerability in SonicWall Network Security Manager's file upload functionality requires immediate attention from teams managing network security infrastructure. The first practical step is to identify all NSM instances, determine their exposure, and confirm business criticality to prioritize remediation efforts.
- Infrastructure and Security teams should own this.
- Verify NSM instance exposure and criticality.
- Plan and coordinate remediation actions.