PT-2024-5026 · Sonicwall · Sonicos

Published

2024-07-17

·

Updated

2024-09-10

·

CVE-2024-40764

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: SonicOS (affected versions not specified)
Description: The issue is related to a heap-based buffer overflow vulnerability in the SonicOS IPSec VPN, which can be exploited by an unauthenticated remote attacker to cause Denial of Service (DoS). This vulnerability is associated with the implementation of the IPSec VPN protocol in the SonicOS operating system, allowing a remote attacker to disrupt service.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-05550
CVE-2024-40764

Affected Products

Sonicos