Executive brief
An improper authentication vulnerability in the SonicWall SonicOS SSLVPN authentication mechanism allows a remote attacker to bypass authentication. This flaw can lead to unauthorized access to the VPN and internal network resources.
Affected products
- SonicWall SonicOS 7.1.1-7040 to 7.1.1-7058, 7.1.2-7019, 8.0.0-8035
- SonicWall NSa 2700
- SonicWall NSa 3700
- SonicWall NSa 4700
- SonicWall NSa 5700
- SonicWall NSa 6700
- SonicWall NSsp 10700
- SonicWall NSsp 11700
- SonicWall NSsp 13700
- SonicWall NSsp 15700
- SonicWall NSv 270
- SonicWall NSv 470
- SonicWall NSv 870
- SonicWall TZ270
- SonicWall TZ370
- SonicWall TZ470
- SonicWall TZ570
- SonicWall TZ670
- SonicWall TZ80
Timeline
- 2025-01-09: disclosed: Initial disclosure by SonicWall PSIRT
- 2025-02-18: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
- 2025-02-18: exploited: CISA confirms active exploitation in the wild