Junglewise Threat Intelligence

CVE-2024-40766: SonicWall SonicOS Improper Access Control Vulnerability

CVE-2024-40766 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-09

Technologies: SonicWall SonicOS. Vendors: SonicWall.

Executive brief

An improper access control vulnerability in SonicWall SonicOS management access allows unauthenticated attackers to gain unauthorized resource access. Under specific conditions, the vulnerability can also be exploited to cause a denial-of-service condition by crashing the firewall.

Affected products

  • SonicWall SonicOS Gen 5 devices; Gen 6 devices; Gen 7 devices running 7.0.1-5035 and older

Timeline

  • 2024-09-09: disclosed
  • 2024-09-09: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2024-09-09: exploited: Reported as exploited in the wild.

Related threats