News

Inadequate Patching Enables Stealthy Auth Bypass

Organizations running SonicWall Gen6 SSL-VPN appliances face a measurable risk of intrusion despite deploying vendor-supplied firmware updates, as threat actors have successfully bypassed multi-factor authentication protections on devices where administrators completed only the software installation step but did not follow through with required manual reconfiguration of LDAP servers. ReliaQuest documented multiple intrusions between February and March 2026 where attackers moved from external access to internal file servers in as little as thirty minutes, deployed Cobalt Strike beacons, and attempted to load vulnerable drivers to disable endpoint protections. The vulnerability, tracked as CVE-2024-12802, requires a seven-step remediation process beyond firmware installation, including deletion of existing LDAP configurations, removal of cached users, and firewall reboot. The gap between perceived protection and actual security posture is not abstract: logs showed normal MFA flows even during successful authentication bypass attempts, leading defenders to incorrect conclusions about control effectiveness.

The root cause is missing MFA enforcement when organizations use the UPN login format on Gen6 devices. If LDAP configurations include userPrincipalName in the qualified login name field, valid credentials alone grant access—MFA policy settings become irrelevant. Gen7 and Gen8 devices don’t have this problem; firmware updates alone fix the vulnerability on those platforms. Security teams may apply identical update procedures across all device generations and assume they’re done, while Gen6 appliances remain vulnerable. SonicWall’s advisory explicitly states that firmware installation without reconfiguration doesn’t mitigate the vulnerability, but ReliaQuest’s incident response work shows this message hasn’t reached everyone who needs to hear it.

Attackers work fast but don’t rush. The intrusions ReliaQuest observed lasted thirty to sixty minutes before attackers logged out—behavior consistent with access brokering rather than immediate ransomware deployment. They ran network reconnaissance, tested credential reuse on internal systems, and exfiltrated data to enable follow-on operations by other threat groups. The Akira ransomware gang hit SonicWall SSL-VPN devices under similar circumstances in 2025, logging in despite active MFA, though the specific method wasn’t confirmed then. Authentication bypass on perimeter devices has become a reliable initial access technique for brokers who need quick, high-confidence results.

The logging problem makes this worse than a simple authentication bypass. Because compromised sessions appear in logs as normal MFA flows, security operations teams reviewing authentication data won’t spot the intrusion. The usual red flags—failed MFA challenges, odd login times, geographic anomalies—never appear. The attacker’s access looks legitimate to the logging subsystem, which delays detection and gives more time for lateral movement. SIEM correlation rules designed to flag MFA bypass attempts won’t fire when this vulnerability gets exploited, even when those rules work perfectly. The control failure produces no logging artifacts, so compromises often go unnoticed until post-exploitation activity triggers alerts later in the attack chain.

Vendors increasingly issue updates that bundle software installation with mandatory configuration changes, but organizations typically implement only the software. ReliaQuest assessed with medium confidence that the intrusions they investigated represent the first in-the-wild exploitation of CVE-2024-12802—attackers successfully compromised multiple environments across different sectors and geographies. The incomplete remediation problem hits hardest when vendor advisories contain multi-step instructions that fall outside standard patch deployment workflows. Security teams accustomed to automated patch distribution often lack processes to track and verify manual post-installation steps, especially when those steps require firewall reboots and service interruptions.

Security leadership needs to ask whether current patch management and validation procedures can detect incomplete remediation before attackers do. Vulnerability scanners check software versions, not configuration states. Gen6 devices running updated firmware but retaining vulnerable LDAP configurations would scan as fully patched in asset management systems. Organizations need verification procedures that go beyond version checking to include configuration validation, particularly for perimeter devices that control access to internal networks. These intrusions demonstrate that the gap between deploying a patch and achieving the intended security outcome can stay open for months—an exploitable window that threat actors already target systematically. Fixing CVE-2024-12802 isn’t just about updating devices; it’s about confirming that security controls actually function as intended after updates go out.

Sources

Contact Us

InfoTransec Inc.

Telephone:
+1 855-INFOSEC (463-6732)

Hours:
9am – 5pm   Weekdays

Address:
The Atrium @ MIP
McMaster Innovation Park
Suite 416A-8
175 Longwood Road South,
Hamilton, ON, L8P 0A1

Nationwide Service

Primarily based out of Hamilton, InfoTransec also services the following areas within Southern Ontario and the GTA.

 Brantford
 Burlington
 Cambridge
 Hamilton
 Kitchener
 London
 Milton
 Mississauga
 Oakville
 St. Catharine’s
 Toronto
 Waterloo

Nationwide service is also available.

Our Tweets
NVD Vulnerabilities
Nationwide Service

Primarily based out of Hamilton, InfoTransec also services the following areas within Southern Ontario and the GTA.

 Brantford
 Burlington
 Cambridge
 Hamilton
 Kitchener
 London
 Milton
 Mississauga
 Oakville
 St. Catharine’s
 Toronto
 Waterloo

Nationwide service is also available.

Our Tweets
NVD Vulnerabilities

© InfoTransec – 2019 – All Rights Reserved | Privacy Policy

Icons made by Freepik from www.flaticon.com is licensed by CC 3.0 BY