An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
The flaw involves improper verification of access permissions in the SonicOS system management module. An unauthenticated remote attacker, without any user interaction, can gain access to protected device resources. Under certain conditions, exploiting this vulnerability can cause the firewall to completely stop functioning (crash), resulting in a break in network service availability.
An attacker can gain unauthorized access to firewall resources, and under specific conditions, cause its failure and thus interrupt network protection and service availability. The full impact includes violations of confidentiality, integrity, and availability (C:H/I:H/A:H).
Patches available from the vendor must be applied immediately in accordance with references published in SonicWall PSIRT (SNWLID-2024-0015). For Gen 7 devices, an update to a version newer than SonicOS 7.0.1-5035 is required. Until the patch is deployed, it is recommended to restrict or block access to the management interface from untrusted networks and the Internet.
SonicWall Firewall generation 5 (Gen 5) and generation 6 (Gen 6) in all SonicOS versions, as well as generation 7 (Gen 7) devices with SonicOS 7.0.1-5035 and earlier. Affected products include: SonicWall SonicOS, SonicWall SOHO, SonicWall NSSP 12400, SonicWall NSSP 12800.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSonicwall Nsa 2650
HWSonicwallall versionsSonicwall Nsa 2700
HWSonicwallall versionsSonicwall Nsa 3600
HWSonicwallall versionsSonicwall Nsa 3650
HWSonicwallall versionsSonicwall Nsa 3700
HWSonicwallall versionsSonicwall Nsa 4600
HWSonicwallall versionsSonicwall Nsa 4650
HWSonicwallall versionsSonicwall Nsa 4700
HWSonicwallall versionsSonicwall Nsa 5600
HWSonicwallall versionsSonicwall Nsa 5650
HWSonicwallall versionsSonicwall Nsa 5700
HWSonicwallall versionsSonicwall Nsa 6600
HWSonicwallall versionsSonicwall Nsa 6650
HWSonicwallall versionsSonicwall Nsa 6700
HWSonicwallall versionsSonicwall Nssp 10700
HWSonicwallall versionsSonicwall Nssp 11700
HWSonicwallall versionsSonicwall Nssp 12400
HWSonicwallall versionsSonicwall Nssp 12800
HWSonicwallall versionsSonicwall Nssp 13700
HWSonicwallall versionsSonicwall Sm 9200
HWSonicwallall versionsSonicwall Sm 9250
HWSonicwallall versionsSonicwall Sm 9400
HWSonicwallall versionsSonicwall Sm 9450
HWSonicwallall versionsSonicwall Sm 9600
HWSonicwallall versionsSonicwall Sm 9650
HWSonicwallall versionsSonicwall Sm9800
HWSonicwallall versionsSonicwall Soho
HWSonicwallall versionsSonicwall Soho 250
HWSonicwallall versionsSonicwall Soho 250w
HWSonicwallall versionsSonicwall Sohow
HWSonicwallall versions
CISA KEV — detailsi
- Vendori
- SonicWall ↗
- Producti
- SonicOS
- Added to KEVi
- September 9, 2024
- Remediation deadline (US Federal)i
- September 30, 2024(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
Related vulnerabilities
SonicWall SonicOS SSLVPN — pominięcie uwierzytelnienia (Auth Bypass)
Buffer overflow w SonicOS umożliwiający DoS i zdalne wykonanie kodu
SonicOS SSL VPN: format string umożliwia zakłócenie usługi bez uwierzytelnienia
Atak przez fałszowanie odpowiedzi w protokole RADIUS (RFC 2865) via kolizja MD5
Pominięcie uwierzytelnienia w SonicWall SonicOS SSL-VPN (auth bypass)