SonicWall Patches 3 Zero-Day Flaws
Compliance
Twitter
SonicWall's headquarters in Milpitas, California (Photo: Arc Tec Inc.)
SonicWall has patched three zero-day vulnerabilities in the hosted and on-premises versions of its Email Security product after attackers began exploiting them last month.
FireEye Mandiant, which uncovered the flaws, says it has seen attackers using the three vulnerabilities to place web shells, or remote access scripts, on systems. That access can then be used to access an organization's email, FireEye says in a blog post. The attackers can also use access to pivot further into victims' systems, often referred to as lateral movement, the security firm adds.