Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A January 2024 scan found 178,637 of 233,984 internet-exposed SonicWall firewalls vulnerable to one or both of two SonicOS flaws. That 76% figure describes the scan sample at that time—not today’s worldwide firewall count. If you manage a SonicWall appliance, check its exact model and firmware against SonicWall’s current advisories, apply the supported fix, and restrict management access to trusted sources.

What the 178,000 figure means

Bishop Fox reported that its scan, using BinaryEdge data, identified 178,637 vulnerable firewalls among 233,984 internet-exposed SonicWall firewalls scanned in 2024. The researchers said 146,116 (62%) were vulnerable to CVE-2022-22274, 178,608 (76%) to CVE-2023-0656, and 146,087 (62%) to both. These are dated scan results, not a current census of all SonicWall devices or proof that every appliance or model is affected. Bishop Fox’s scan report and BleepingComputer’s January 15, 2024 coverage describe the findings.

BleepingComputer separately cited Shadowserver data indicating more than 500,000 SonicWall firewalls exposed online, including over 328,000 in the United States, at the time of its report. Those, too, are January 2024 figures and should not be read as current exposure counts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the two SonicOS vulnerabilities can do

CVE-2022-22274

This flaw was reported as a stack-based buffer overflow reachable through HTTP. It could cause denial of service and potentially enable remote code execution. The possibility of remote code execution is not the same as evidence that an attacker successfully executed code on a particular device.

#1 Best Overall
SonicWall TZ470 Network Security/Firewall Appliance
  • The latest SonicWall TZ470 series, are the first desktop form factor nextgeneration firewalls (NGFW) with 1 or 5 Gigabit Ethernet interfaces. The series consist of a wide range of products to suit a variety of use cases.
  • Reduce complexity and get the business running without relying on IT personnel with easy onboarding using SonicExpress App and Zero-Touch Deployment, and easy management through a single pane of glass
  • Drive business growth by investing in next-gen appliances with multi-gigabit and advanced security features, to future-proof against the changing network and security landscape
  • Ensure seamless communication as stores talk to HQ via easy VPN connectivity which allows IT administrators to create a hub and spoke configuration for the safe transport of data between all locations
  • Hardware: Operating system: SonicOS 7. | Interfaces: 8x1GbE, 2x1GbE, 2 USB 3., 1 Console | Management: Network Security Manager, CLI, SSH, Web UI, GMS, REST APIs | VLAN interfaces: 128 | Access points supported (maximum): 32

CVE-2023-0656

This was also reported as a stack-based buffer overflow, with denial of service as the stated impact. Bishop Fox’s account says its initial investigation found the vulnerable code was the same issue the vendor later announced as CVE-2023-0656.

Repeated crashes can force an appliance into maintenance mode, requiring administrator intervention. While the firewall is disrupted, protected network traffic and VPN access may be affected. The precise impact depends on the appliance and the environment.

Rank #2
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

How to check and remediate an appliance

  1. Identify the exact appliance and firmware. Record the model and the currently running SonicOS version from your appliance’s administration interface or established inventory.
  2. Check SonicWall’s official advisories. Find the current guidance for SNWLID-2022-0003 and SNWLID-2023-0004. Confirm that the advisory applies to your model and use its current fixed-version instructions. Do not infer a fixed firmware release from the historical scan or from a different appliance model.
  3. Install the supported fixed firmware. Follow SonicWall’s model-specific upgrade guidance and your organization’s change-control and backup procedures. If the appliance is centrally managed, coordinate the upgrade with the responsible administrator.
  4. Limit management access. Restrict the management interface to trusted addresses or networks and remove access from untrusted internet sources. This reduces exposure; it does not replace applying the vendor’s fix.
  5. Verify service after the change. Confirm the appliance is running the intended firmware and that firewall policies, VPN access, and administrative connectivity work as expected.

If you cannot confidently identify the model, confirm the applicable firmware, or safely perform the change, involve a qualified firewall administrator. Regional advisories from Trinidad and Tobago CSIRT and Peru’s Centro Nacional de Seguridad Digital also covered these vulnerabilities in January 2024.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What January 2024 reporting did—and did not—establish

BleepingComputer reported on January 15, 2024 that SonicWall PSIRT had “no knowledge that these vulnerabilities have been exploited in the wild.” It also reported that a proof of concept for CVE-2022-22274 was available. The PSIRT statement is a historical status, not confirmation of the present-day exploitation situation; the available evidence here does not establish current exploitation activity.

Rank #3
Sonicwall NSA 2700 (02-SSC-4324)
  • The SonicWall Network Security appliance (NSa) Mid-Range Firewall is next-generation security designed specifically for businesses of 250 users and up.
  • Secure Remote Workers - SonicWall NetExtender provides an intuitive SSL-VPN connection client that’s easy to deploy and configure. Easily provide your remote workers with secure access to your corporate network from Linux, Mac and Windows devices.
  • Built-in Wireless Controller - Implement high-speed wireless security by combining a NSa Series next-generation firewall with a SonicWall SonicWave wireless access point. NSa Series firewalls and SonicWave access points both feature 2.5 GbE ports that enable multi-gigabit wireless throughput offered in Wave 2 wireless technology.
  • With cloud-based and on-box capabilities like TLS/SSL decryption and inspection, application intelligence and control, secure SD-WAN, real-time visualization, and WLAN management, SonicWall provides flexible, fast and cost-effective security to keep the threats out and your business thriving.
  • Highlights: 1 RU – Form Factor | 16 x 1 GbE interfaces | 3 x 10 GbE interfaces | 2 Gbps Threat and Malware Analysis Throughput | Enterprise Internet Edge Ready

Likewise, the historical scan does not establish today’s number of exposed devices or provide a current model-and-firmware vulnerability matrix. Use SonicWall’s live advisories for the affected versions and supported remediation for your specific appliance.