ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

5,000+ SonicWall firewalls still open to attack (CVE-2024-53704)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40766
Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls)

CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile).

Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents.

9.818% KEV ransomware
  • SonicWall SonicOS (Gen 5 firewalls) Gen 5 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 6 firewalls) Gen 6 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 7 firewalls) SonicOS 7.0.1-5035 and older
mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances)
CVE-2024-53704
Authentication Bypass in SonicWall SonicOS SSLVPN

CVE-2024-53704 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in the SSLVPN authentication mechanism of SonicWall's SonicOS. A remote, unauthenticated attacker can exploit it over the network without user interaction, bypassing SSLVPN authentication to gain unauthorized access to the VPN and a foothold into protected internal networks. CISA notes known ransomware use, making this a high-value entry point for follow-on attacks. Any organization running SonicWall SonicOS with SSLVPN enabled is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-18, public scans show 5,000+ internet-exposed SonicWall firewalls still unpatched, and EPSS rates the 30-day exploitation probability at 95.1%.

Do: Upgrade affected SonicOS deployments to the patched releases listed in SonicWall's advisory, prioritizing internet-facing SSLVPN endpoints. Until patched, restrict or disable SSLVPN exposure where feasible and hunt for signs of exploitation, since ransomware use is known. Remediation must satisfy CISA KEV required actions (apply vendor mitigations or discontinue use).

9.895% KEV ransomware
  • SonicWall SonicOS
largeestimated tens of thousands of SSLVPN-enabled SonicWall firewall deployments, with at least ~5,000 confirmed still exposed and unpatched on the public internet
CVE-2025-23006
Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances

CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published.

Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections.

9.823% KEV ransomware
  • SonicWall SMA1000 Appliances — Appliance Management Console (AMC) and Central Management Console (CMC)
largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed
Full article678 words · extracted from helpnetsecurity.com · click to collapse

5,000+ SonicWall firewalls are still vulnerable to attack via a high-severity vulnerability (CVE-2024-53704) that, according to SonicWall, should be considered “at imminent risk of exploitation”.

sonicwall firewalls vulnerability CVE-2024-53704

The warning came last week from Bishop Fox researchers, after they successfully exploited the vulnerability on unpatched SonicWall firewalls and announced they will be releasing details of their exploit code on February 10.

“Although significant reverse-engineering effort was required to find and exploit the vulnerability, the exploit itself is rather trivial,” they noted.

While there is currently no indication that attackers have managed to create their own exploit and use it, it previously took Akira and Fog ransomware outfits mere weeks (and possibly days) after a patch release to devise an exploit for CVE-2024-40766, an improper access control vulnerability in the SonicWall SonicOS management access and SSL VPN.

A fix for CVE-2024-53704 is available

New firmware that fixes CVE-2024-53704, an improper authentication vulnerability in the SonicOS’s SSLVPN authentication mechanism which allows remote attacker to bypass authentication, has been released on January 7, 2024.

The list of platforms and build versions affected by CVE-2024-53704 includes:

  • Gen7 firewalls (TZ270, TZ270W, TZ370, TZ370W, TZ470, TZ470W, TZ570, TZ570W, TZ570P, TZ670, NSa 2700, NSa 3700,NSa 4700, NSa 5700, NSa 6700, NSsp 10700, NSsp 11700, NSsp 13700, NSsp 15700)
  • Gen7 NSv virtual firewalls (NSv 270, NSv 470, NSv 870)
  • TZ80 (a subscription-based next-generation firewall for small offices, home offices, and IoT)

By sending an email notification to its partners, SonicWall additionally emphasized the importance of quickly mitigating the threat by implementing the security update.

“To minimize the potential impact of SSL VPN vulnerabilities, please ensure that access is limited to trusted sources, or disable SSL VPN access from the Internet,” the company added.

Last Thursday, Bishop Fox researchers confirmed that the vulnerability can be exploited remotely and without authentication, and that it enables hijacking of active SSL VPN client sessions.

“An attacker with control of an active SSL VPN session can read the user’s Virtual Office bookmarks, obtain a client configuration profile for NetExtender, open a VPN tunnel, access private networks available to the hijacked account, and log out the session (terminating the user’s connection as well),” they shared.

They also decided not to make attackers’ lives easier by releasing more details about the flaw and the exploit, and to allow organizations enough time to patch before going public with it.

A few days ago, SonicWall has warned about attackers taking advantage of CVE-2025-23006, a critical vulnerability affecting its Secure Mobile Access (SMA) 1000 Series appliances.

In 2021 attackers leveraged three zero-day flaws in SonicWall Email Security appliances.

UPDATE (January 29, 2025, 04:30 a.m. ET):

Rapid7 has released technical details about CVE-2024-53704, a proof-of-concept exploit, and potential indicators of compromise.

Based on their research, CVE-2024-53704 is exploitable in the default SSLVPN configuration, exploitation does not require the knowledge of an existing username or password and attackers can effectively bypass multi-factor authentication protections.

“In order to compromise a user’s account, the user must actively be logged in at the time of exploitation. Notably, exploitation is intrusive; the user’s SSLVPN connection will be repeatedly terminated and reconnected while the threat actor hijacks the connection,” Rapid7 vulnerability researcher Ryan Emmons noted.

“I’ve assigned the Attacker Value as ‘Very High’, since the exploit facilitates unauthenticated initial access on a system typically exposed to the public internet. I’ve assigned the exploitability as ‘High’, since the exploit does cause some disruption to normal user activity, and internal network access can be choppy.”

UPDATE (February 10, 2025, 01:00 p.m. ET):

Bishop Fox have released full details on how CVE-2024-53704 can be exploited.

“As of February 7, 2025, our scans indicate approximately 4,500 internet-facing SonicWall SSL VPN servers remain unpatched against CVE-2024-53704. If you have not yet upgraded your SonicWall firewalls to the latest available firmware, please follow SonicWall’s advice and upgrade immediately,” they added.

UPDATE (February 14, 2025, 05:30 p.m. ET):

Arctic Wolf has observed attackers targeting SonicWall firewalls via CVE-2024-53704.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/27/5000-sonicwall-firewalls-still-open-to-attack-vulnerability-cve-2024-53704/