PT-2024-5748 · Sonicwall · Sonicos
Published
2024-08-22
·
Updated
2026-07-12
·
CVE-2024-40766
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SonicWall Firewall Gen 5 (affected versions not specified)
SonicWall Firewall Gen 6 (affected versions not specified)
SonicWall SonicOS versions prior to 7.0.1-5035
Description
An improper access control issue exists in the SonicWall SonicOS management access, which can allow unauthorized access to resources and, under certain conditions, cause the firewall to crash. This flaw has been actively exploited by threat actors, including the Akira ransomware group, to gain initial network access, bypass multi-factor authentication (MFA), and move laterally through environments, including virtual machines on Nutanix AHV, VMware ESXi, and Hyper-V. In one instance, this was used in a supply chain attack affecting 74 US banks and credit unions via a third-party vendor. Technical analysis indicates that attackers may obtain OTP seeds or secrets to generate valid codes and bypass MFA. Additionally, the issue is exacerbated when local user passwords are carried over during migrations from Gen 6 to Gen 7 devices without being reset.
Recommendations
For SonicWall SonicOS versions prior to 7.0.1-5035, update firmware to version 7.3.0 to obtain enhanced protections against brute force attacks and additional MFA controls.
As a temporary mitigation, disable SNMP traps before upgrading to version 7.3.0 to prevent potential firewall crashes.
Reset all local user account passwords for any accounts with SSLVPN access, particularly those migrated from Gen 6 to Gen 7 devices.
Remove all unused or inactive local user accounts.
Enforce strong password policies and configure MFA/TOTP policies.
Enable account lockout and password complexity settings in version 7.3.
Enable Botnet Protection and Geo-IP Filtering.
Restrict Virtual Office Portal access to the internal network.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonicos