Executive Summary
In June 2024, SonicWall confirmed a security incident impacting its MySonicWall.com portal, where threat actors gained unauthorized access to backup firewall configuration files belonging to fewer than 5% of their customers. The attackers employed targeted brute-force attacks to access encrypted preference files stored in the cloud, potentially exposing sensitive network architecture and policy information. While SonicWall promptly disabled the affected backup feature, notified law enforcement and affected customers, and engaged incident response specialists, the exposure raises substantial risk of follow-on attacks and exploitation due to the detailed nature of the data compromised.
This incident highlights a growing concern with threats targeting cloud-managed administrative platforms, especially those operated by key infrastructure vendors. As attackers pivot from device exploits to systemic attacks on cloud portals, organizations must scrutinize cloud data storage and vendor security practices more rigorously to mitigate downstream and supply chain risks.
Why This Matters Now
This breach illustrates the urgent need for stronger cloud infrastructure security and visibility, particularly for platforms controlling critical configuration data. As reliance on vendor-managed portals increases, these attack vectors become more attractive to sophisticated adversaries, demanding immediate attention to supply chain and cloud security hygiene.
Attack Path Analysis
Attackers conducted targeted brute-force attacks against MySonicWall.com accounts, resulting in the unauthorized access of customer cloud backups for firewall configurations. With valid credentials in hand, they escalated access to reach stored preference files associated with multiple accounts. This may have enabled potential movement across customer accounts or internal resources, increasing the risk of broader exposure. Communication with adversary-controlled infrastructure could have been established to execute further malicious actions. Threat actors then exfiltrated configuration files containing sensitive network topology data, increasing the risk of subsequent attacks leveraging this intelligence. The leak of such data could lead to increased compromise of customer environments, easier exploitation of firewalls, and ultimately undermine trust in SonicWall’s ecosystem.
Kill Chain Progression
Initial Compromise
Description
Adversaries initiated large-scale brute force attacks against MySonicWall.com portal accounts to gain unauthorized access.
Related CVEs
CVE-2024-40766
CVSS 9.3An improper access control vulnerability in SonicOS management access and SSLVPN allows unauthorized resource access and can cause firewall crashes.
Affected Products:
SonicWall SonicOS – Gen 5: SOHO devices running version 5.9.2.14-12o and older, Gen 6: TZ, NSA, and SM models running versions 6.5.4.14-109n and older, Gen 7: TZ and NSA models running SonicOS build version 7.0.1-5035 and older
Exploit Status:
exploited in the wildReferences:
https://nvd.nist.gov/vuln/detail/CVE-2024-40766https://www.sonicwall.com/support/product-notification/product-notice-improper-access-control-vulnerability-in-sonicos/240822062732757https://www.rapid7.com/blog/post/2024/09/09/etr-cve-2024-40766-critical-improper-access-control-vulnerability-affecting-sonicwall-devices/CVE-2024-53704
CVSS 9.8An improper authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Affected Products:
SonicWall SonicOS – 7.1.x (7.1.1-7058 and older), 7.1.2-7019, 8.0.0-8035
Exploit Status:
exploited in the wildCVE-2024-40762
CVSS 7.1Use of a cryptographically weak pseudo-random number generator in the SSLVPN authentication token generator can result in authentication bypass.
Affected Products:
SonicWall SonicOS – Gen 6 devices, Gen 7 devices, TZ80 series
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Brute Force
Valid Accounts
Credentials from Password Stores: Credentials in Cloud Storage
Data from Cloud Storage Object
Automated Exfiltration
Account Discovery
Impair Defenses: Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Access to Systems
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA Zero Trust Maturity Model 2.0 – Authentication Strength and Access Controls
Control ID: Identity Pillar – Authentication & Access Control
NIS2 Directive – Incident Handling – Ensuring Integrity and Confidentiality
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Cloud infrastructure compromise exposing firewall configurations threatens compliance with PCI DSS requirements and enables attackers to bypass critical financial transaction security controls.
Health Care / Life Sciences
MySonicWall breach exposes network architecture violating HIPAA encryption standards, potentially enabling lateral movement attacks against patient data and medical device networks.
Government Administration
Firewall configuration exposure creates national security risks by revealing government network topologies, enabling state-sponsored actors to exploit critical infrastructure and sensitive systems.
Computer/Network Security
SonicWall's cloud portal compromise undermines vendor trust and demonstrates systemic security failures affecting cybersecurity firms relying on SonicWall's firewall management infrastructure.
Sources
- Attack on SonicWall’s cloud portal exposes customers’ firewall configurationshttps://cyberscoop.com/sonicwall-cyberattack-customer-firewall-configurations/Verified
- Product Notice: Improper Access Control Vulnerability in SonicOShttps://www.sonicwall.com/support/product-notification/product-notice-improper-access-control-vulnerability-in-sonicos/240822062732757Verified
- CISA Confirms Exploitation of SonicWall Vulnerabilitieshttps://www.infosecurity-magazine.com/news/cisa-exploitation-sonicwall/Verified
- SonicWall Breach Exposes Firewall Configuration Backupshttps://www.quorumcyber.com/threat-intelligence/sonicwall-breach-exposes-firewall-configuration-backups-mandatory-credential-resets-recommended/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, centralized visibility, and strict policy enforcement at the cloud network and identity layer would have substantially reduced the attack surface, limited unauthorized access, constrained lateral movement, and prevented exfiltration of sensitive data. CNSF-aligned controls—such as zero trust segmentation, traffic anomaly detection, and real-time egress policy enforcement—each play a critical role in breaking this cloud-specific kill chain.
Control: Multicloud Visibility & Control
Mitigation: Early detection and alerting on suspicious authentication attempts.
Control: Zero Trust Segmentation
Mitigation: Limited attacker access to only authorized resources tied to their identity.
Control: East-West Traffic Security
Mitigation: Blocked unauthorized intra-portal movement and segmentation violations.
Control: Threat Detection & Anomaly Response
Mitigation: Real-time detection and responsive disruption of anomalous outbound sessions.
Control: Egress Security & Policy Enforcement
Mitigation: Stops unauthorized outbound data transfer to adversary infrastructure.
Continuous, inline policy adapts to contain blast radius and automate response steps.
Impact at a Glance
Affected Business Functions
- Network Security Management
- Remote Access Services
- VPN Connectivity
Estimated downtime: 3 days
Estimated loss: $500,000
Exposure of firewall configuration backups containing encrypted credentials, network configurations, and security policies, potentially facilitating unauthorized access and exploitation.
Recommended Actions
Key Takeaways & Next Steps
- • Immediately enable centralized visibility and automated monitoring for both authentication and data access events in all customer-facing cloud portals.
- • Implement Zero Trust segmentation by enforcing least privilege, identity-based access policies, and microsegmentation within cloud management planes.
- • Deploy robust east-west and egress policy enforcement to detect and prevent lateral movement and unauthorized data transfers across cloud environments.
- • Continuously baseline user and service behavior to power anomaly detection and reduce dwell time for malicious actors.
- • Regularly audit and restrict cloud backup, export, and API functionalities, ensuring backups are encrypted, access is minimized, and strong controls are in place.



