ZeroHour

CVE-2024-40766

KEV ransomwaremass1

Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls)

CISA: SonicWall SonicOS Improper Access Control Vulnerability

CVSS 3.1
9.8 critical
EPSS
18%p97
Published
()
KEV added
AI analysis

CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile).

What to do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents.

Affected
SonicWall SonicOS (Gen 5 firewalls)Gen 5 appliances, all versions per the CISA advisory
SonicWall SonicOS (Gen 6 firewalls)Gen 6 appliances, all versions per the CISA advisory
SonicWall SonicOS (Gen 7 firewalls)SonicOS 7.0.1-5035 and older
Estimated exposure
mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances) — SonicWall's installed base spans more than a million appliances, and public internet scans (Shodan/Censys) regularly show on the order of hundreds of thousands of reachable SonicWall SSLVPN and management endpoints, with legacy Gen 5/6 and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CISA Known Exploited Vulnerability
Affected
SonicWall SonicOS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
sonicos
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news