ZeroHour
Security Affairspublished ()ingested @securityaffairs

Attackers exploit valid logins in SonicWall SSL VPN compromise

highRansomwareimportance 60CVE-2024-40766

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-40766
Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls)

CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile).

Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents.

9.818% KEV ransomware
  • SonicWall SonicOS (Gen 5 firewalls) Gen 5 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 6 firewalls) Gen 6 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 7 firewalls) SonicOS 7.0.1-5035 and older
mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances)
Full article491 words · extracted from securityaffairs.com · click to collapse

Huntress warns of widespread SonicWall SSL VPN breaches, with attackers using valid credentials to access multiple accounts rapidly.

Cybersecurity firm Huntress warned of a widespread compromise of SonicWall SSL VPNs, with threat actors using valid credentials to access multiple customer accounts rapidly.

“As of October 10, Huntress has observed widespread compromise of SonicWall SSLVPN devices across multiple customer environments. Threat actors are authenticating into multiple accounts rapidly across compromised devices.” reads the report published by Huntress. “The speed and scale of these attacks imply that the attackers appear to control valid credentials rather than brute-forcing.”

Since October 4, over 100 SonicWall SSL VPN accounts across 16 customers were compromised using valid credentials, not brute force. According to Huntress, logins originated from IP 202.155.8[.]73. Some attackers disconnected quickly, while others conducted post-exploitation, scanning networks and probing local Windows accounts.

SonicWall recently warned that attackers accessed firewall backup files from its cloud service, exposing encrypted credentials and configs.

In September, SonicWall urged customers to reset credentials after firewall backup files tied to MySonicWall accounts were exposed. The company announced it had blocked attackers’ access and is working with cybersecurity experts and law enforcement agencies to determine the scope of the breach.

SonicWall initially said that under 5% of customers were impacted, no files leaked, but the breach still poses risks that need urgent action.

The incident impacted SonicWall Firewalls with preference files backed up in MySonicWall.com

SonicWall urged customers to log into their MySonicWall accounts and check if cloud backups are enabled. If not, there’s no risk. If yes, look for any flagged serial numbers, these indicate affected firewalls that need immediate remediation. If you’ve used backups but see no flagged devices, SonicWall will share further guidance soon.

The company told affected customers to import new preference files. However, importing the new file disrupts IPSec VPNs, TOTP bindings, and user access. After import, users must reconfigure VPN pre-shared keys and reset TOTP along with user passwords. To reduce downtime, SonicWall recommends importing during maintenance windows, off-hours, or low-activity periods since the process reboots the firewall immediately.

On October 8, SonicWall confirmed that threat actors accessed the preference files of all firewalls using its MySonicWall cloud backup service.

SonicWall said the stolen files contain encrypted credentials and configs, which could aid attacks. They are notifying affected users and providing assessment tools. Updated device lists now classify impacted firewalls by priority to guide remediation.

The disclosure coincides with rising ransomware attacks exploiting SonicWall flaw CVE-2024-40766 to deploy Akira ransomware. Darktrace observed an August 2025 intrusion on a U.S. firm involving scanning, lateral movement, privilege escalation, and data exfiltration.

“Starting in July 2025, Akira ransomware attacks surged globally, targeting SonicWall SSL VPN devices. In August, Darktrace detected suspicious activity in a US network, including scanning, lateral movement, and data exfiltration.” reported DarkTrace. “A compromised SonicWall VPN server linked the incident to the broader Akira campaign exploiting known vulnerabilities.”

Pierluigi Paganini

(SecurityAffairs – hacking, ransomware)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/183245/hacking/attackers-exploit-valid-logins-in-sonicwall-ssl-vpn-compromise.html