|
|
| |
| SonicWALL SOHO2 is a comprehensive and affordable Internet security solution for small offices with limited network experience. A vulnerability in the product that allows internal users to cause a Denial of Service attack against the Firewall. |
| |
Credit:
The information has been provided by Raptor and Todd Koopman.
|
| |
Vulnerable systems:
SonicWALL SOHO2 firmware version 5.0.0, ROM version 4.0.0
Sending a very long string (several hundreds of characters) as the Username in the authentication page of the SonicWALL web server will cause the Firewall to react strangely: it begins to refuse connections to the 80/tcp port and it stops routing packets from the internal LAN. After about 30 seconds, it will return to its normal behavior.
Vendor status:
The vendor has been contacted and is planning to release a patch.
|
|
|
|
|
|
|
|