CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-40766

CVSS 9.8v3.1pub. 2024-08-23upd. 2025-10-31

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

🤖 AI Analysis
How it works

The flaw involves improper verification of access permissions in the SonicOS system management module. An unauthenticated remote attacker, without any user interaction, can gain access to protected device resources. Under certain conditions, exploiting this vulnerability can cause the firewall to completely stop functioning (crash), resulting in a break in network service availability.

Impact

An attacker can gain unauthorized access to firewall resources, and under specific conditions, cause its failure and thus interrupt network protection and service availability. The full impact includes violations of confidentiality, integrity, and availability (C:H/I:H/A:H).

Mitigation & patch

Patches available from the vendor must be applied immediately in accordance with references published in SonicWall PSIRT (SNWLID-2024-0015). For Gen 7 devices, an update to a version newer than SonicOS 7.0.1-5035 is required. Until the patch is deployed, it is recommended to restrict or block access to the management interface from untrusted networks and the Internet.

Who is affected

SonicWall Firewall generation 5 (Gen 5) and generation 6 (Gen 6) in all SonicOS versions, as well as generation 7 (Gen 7) devices with SonicOS 7.0.1-5035 and earlier. Affected products include: SonicWall SonicOS, SonicWall SOHO, SonicWall NSSP 12400, SonicWall NSSP 12800.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sonicwall Nsa 2650

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 2700

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 3600

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 3650

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 3700

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 4600

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 4650

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 4700

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 5600

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 5650

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 5700

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 6600

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 6650

    HW
    Sonicwall
    all versions
  • Sonicwall Nsa 6700

    HW
    Sonicwall
    all versions
  • Sonicwall Nssp 10700

    HW
    Sonicwall
    all versions
  • Sonicwall Nssp 11700

    HW
    Sonicwall
    all versions
  • Sonicwall Nssp 12400

    HW
    Sonicwall
    all versions
  • Sonicwall Nssp 12800

    HW
    Sonicwall
    all versions
  • Sonicwall Nssp 13700

    HW
    Sonicwall
    all versions
  • Sonicwall Sm 9200

    HW
    Sonicwall
    all versions
  • Sonicwall Sm 9250

    HW
    Sonicwall
    all versions
  • Sonicwall Sm 9400

    HW
    Sonicwall
    all versions
  • Sonicwall Sm 9450

    HW
    Sonicwall
    all versions
  • Sonicwall Sm 9600

    HW
    Sonicwall
    all versions
  • Sonicwall Sm 9650

    HW
    Sonicwall
    all versions
  • Sonicwall Sm9800

    HW
    Sonicwall
    all versions
  • Sonicwall Soho

    HW
    Sonicwall
    all versions
  • Sonicwall Soho 250

    HW
    Sonicwall
    all versions
  • Sonicwall Soho 250w

    HW
    Sonicwall
    all versions
  • Sonicwall Sohow

    HW
    Sonicwall
    all versions

CISA KEV — detailsi

Vendori
SonicWall
Producti
SonicOS
Added to KEVi
September 9, 2024
Remediation deadline (US Federal)i
September 30, 2024(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 30 września 2024
Tags
Firewall
CWE
References

Related vulnerabilities

CVE-2024-53704CRITICAL9.8⚠ KEVPL ✓same product

SonicWall SonicOS SSLVPN — pominięcie uwierzytelnienia (Auth Bypass)

CVE-2020-5135CRITICAL9.8⚠ KEVPL ✓same product

Buffer overflow w SonicOS umożliwiający DoS i zdalne wykonanie kodu

CVE-2025-40600CRITICAL9.8PL ✓same product

SonicOS SSL VPN: format string umożliwia zakłócenie usługi bez uwierzytelnienia

CVE-2024-3596CRITICAL9.0PL ✓same product

Atak przez fałszowanie odpowiedzi w protokole RADIUS (RFC 2865) via kolizja MD5

CVE-2024-22394CRITICAL9.8PL ✓same product

Pominięcie uwierzytelnienia w SonicWall SonicOS SSL-VPN (auth bypass)