PT-2024-5748 · Sonicwall · Sonicos
Published
2024-08-22
·
Updated
2025-09-17
·
CVE-2024-40766
9.8
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
SonicWall SonicOS versions prior to 7.3.0.
**Description:**
SonicWall SonicOS contains an improper access control vulnerability (CVE-2024-40766) that could allow unauthorized access to resources and, in specific conditions, cause the firewall to crash. The Akira ransomware group is actively exploiting this vulnerability, particularly in SSL VPN deployments. Approximately 48,933 SonicWall devices remain vulnerable. Attackers are exploiting default configurations and weak passwords, especially in systems recently migrated from Gen 6 to Gen 7 without password resets. The vulnerability affects Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
**Recommendations:**
* Update SonicOS to version 7.3.0 or later.
* Reset all local user account passwords for any accounts with SSLVPN access.
* Enable Multi-Factor Authentication (MFA).
* Remove unused or inactive user accounts.
* Enable Botnet Protection and Geo-IP Filtering.
* Restrict SSLVPN access to trusted IP addresses.
* Review and audit recent configuration changes for unusual activity.
* Rotate any credentials that may have been exposed.
* Disable SNMP traps before upgrading to version 7.3.0.
Fix
Improper Access Control
Weakness Enumeration
Related Identifiers
Affected Products
References · 325
- https://nvd.nist.gov/vuln/detail/CVE-2024-40766 · Security Note
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015 · Security Note, Vendor Advisory
- https://bdu.fstec.ru/vul/2024-06461 · Security Note
- https://twitter.com/transilienceai/status/1854935781993070658 · Twitter Post
- https://twitter.com/catnap707/status/1966250329479209329 · Twitter Post
- https://twitter.com/XynikIT/status/1832110889727582630 · Twitter Post
- https://twitter.com/moton/status/1832070948838899952 · Twitter Post
- https://t.me/aptreports/16054 · Telegram Post
- https://twitter.com/f1tym1/status/1848561145600180443 · Twitter Post
- https://twitter.com/LBTTechGroup/status/1833233963210445002 · Twitter Post
- https://twitter.com/XArthurDent/status/1833285728027218130 · Twitter Post
- https://twitter.com/AladdinCyberae/status/1833472312865083418 · Twitter Post
- https://twitter.com/transilienceai/status/1838204541717672352 · Twitter Post
- https://twitter.com/transilienceai/status/1856386507516572094 · Twitter Post
- https://twitter.com/transilienceai/status/1966344398444044572 · Twitter Post