An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
The error classified as CWE-287 (Improper Authentication) lies in the authentication mechanism of the SSLVPN interface in SonicOS. An attacker can send a specially crafted network request to the vulnerable device without providing valid credentials, and the flawed identity verification implementation results in access being granted. The attack requires no prior privileges or user interaction, and the network vector (AV:N) means it can be performed entirely remotely over the Internet.
Successful exploitation of the vulnerability allows an attacker to gain unauthorized access to protected network infrastructure, potentially leading to complete compromise of confidentiality, integrity, and availability of resources accessible through VPN. In practice, this may result in takeover of the organization's internal network.
Patches available from the manufacturer should be applied immediately in accordance with security bulletin SNWLID-2025-0003 published by SonicWall PSIRT. If immediate updates are not possible, it is recommended to temporarily disable or restrict access to the SSLVPN interface from the public network until the patch is deployed.
SonicWall SonicOS on devices: NSA 2700, NSA 3700, NSA 4700, and other SonicWall products from the SonicOS line equipped with SSLVPN functionality — specific firmware versions indicated in manufacturer references (SNWLID-2025-0003).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSonicwall Nsa 2700
HWSonicwallall versionsSonicwall Nsa 3700
HWSonicwallall versionsSonicwall Nsa 4700
HWSonicwallall versionsSonicwall Nsa 5700
HWSonicwallall versionsSonicwall Nsa 6700
HWSonicwallall versionsSonicwall Nssp 10700
HWSonicwallall versionsSonicwall Nssp 11700
HWSonicwallall versionsSonicwall Nssp 13700
HWSonicwallall versionsSonicwall Nssp 15700
HWSonicwallall versionsSonicwall Nsv 270
HWSonicwallall versionsSonicwall Nsv 470
HWSonicwallall versionsSonicwall Nsv 870
HWSonicwallall versionsSonicwall Sonicos
OSSonicwall7.1.2-70198.0.0-80357.1.1-7040 – 7.1.1-7058Sonicwall Tz270
HWSonicwallall versionsSonicwall Tz270w
HWSonicwallall versionsSonicwall Tz370
HWSonicwallall versionsSonicwall Tz370w
HWSonicwallall versionsSonicwall Tz470
HWSonicwallall versionsSonicwall Tz470w
HWSonicwallall versionsSonicwall Tz570
HWSonicwallall versionsSonicwall Tz570p
HWSonicwallall versionsSonicwall Tz570w
HWSonicwallall versionsSonicwall Tz670
HWSonicwallall versionsSonicwall Tz80
HWSonicwallall versions
CISA KEV — detailsi
- Vendori
- SonicWall ↗
- Producti
- SonicOS
- Added to KEVi
- February 18, 2025
- Remediation deadline (US Federal)i
- March 11, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
Related vulnerabilities
Nieprawidłowa kontrola dostępu w SonicWall SonicOS — RCE i crash firewalla
Buffer overflow w SonicOS umożliwiający DoS i zdalne wykonanie kodu
SonicOS SSL VPN: format string umożliwia zakłócenie usługi bez uwierzytelnienia
Atak przez fałszowanie odpowiedzi w protokole RADIUS (RFC 2865) via kolizja MD5
Pominięcie uwierzytelnienia w SonicWall SonicOS SSL-VPN (auth bypass)