12 Feb 2025
Biztonsági szemle
Addressed high-severity SonicWall firewall bug poses VPN hijacking threat
Potential intrusions commence with the delivery of a specially crafted session cookie with a base64-encoded null bytes string to the '/cgi-bin/sslvpnclient' SSL VPN authentication endpoint, prompting an improper session validation that logs out firewall users and enables attacker session hijacking, a report from Bishop Fox revealed.
Read more