>> All posts

Exposed SonicWall Virtual Office logins and password spraying

The short version: A SonicWall Virtual Office portal exposed to the internet lets attackers quietly spray common and already-breached passwords across accounts until one works — turning an exposed VPN login into a way onto your internal network.

What you need to know

There's no CVE here and nothing to patch. The weakness is the combination of exposure and weak authentication: SonicWall Virtual Office is the SSL-VPN self-service portal, meant to be internet-facing so remote users can connect — which means the login is reachable by attackers too, in front of accounts whose passwords may be guessable, reused, or already in a breach dump.

  • How they find it — routine internet-wide scanning and crawling surface exposed SonicWall Virtual Office portals.
  • How they use it — automated, low-and-slow password spraying with common and previously-breached passwords, staying under lockout thresholds.
  • What it leads to — a VPN portal is a doorway into the network. One working credential can grant remote access that reaches internal systems, which is exactly why VPN logins are a favored target for initial access.

How serious we see it

High — by default, with honest upside risk. A VPN portal protected by strong, unique credentials and enforced MFA is a manageable exposure, not an emergency, which is why we don't cry "Critical" on sight. But the severity is a function of what's behind the door: because this fronts network access, if any account uses a weak or reused password and MFA isn't enforced, it quickly becomes High — a direct path from the internet onto your internal network. The reassuring part is that it's entirely in your hands to fix, with no vendor patch required.

What to do

  • Enforce MFA on every VPN account — the single highest-value control; it defeats spraying even when a password is known.
  • Kill weak and reused passwords — enforce strong, unique credentials and check them against known-breached lists.
  • Restrict access where practical — limit the portal to expected geographies or IP ranges if your user base allows.
  • Limit and monitor failed logins — rate-limit attempts and alert on spray patterns (many accounts, few passwords, low-and-slow).
  • Confirm your exposure first — verify which SonicWall Virtual Office portals are reachable from the internet.

How BreachRisk sees it

BreachRisk discovers SonicWall Virtual Office portals in your external footprint the way an attacker would — by crawling it — and then, where authorized, goes a step further than a scanner: it safely attempts a bounded, rate-limited authentication check using exposed (breach-corpus) and common credentials, within strict non-disruptive limits rather than a brute-force flood. That's the honest difference between detecting a VPN login and demonstrating whether it actually holds — turning "we have a SonicWall VPN portal on the internet" into a straight answer.

References

See your cyber risk, proven.