Skip to main content

CVE-2024-40766 could lead to unauthorised access or denial-of-service

Summary

CVE-2024-40766 could lead to unauthorised access or denial-of-service

Affected platforms

The following platforms are known to be affected:

The following platforms are known to be affected:

Threat details

Introduction

SonicWall has released a security advisory to address a critical vulnerability in SonicOS management access and SSLVPN, affecting their SOHO (Generation 5), Generation 6, and Generation 7 appliances. SonicWall appliances are security appliances that provide virtual private network (VPN) and 'next-gen' firewall capabilities. The SonicWall advisory has been updated to reflect reports of exploitation.

CVE-2024-40766 is an 'Improper Access Control' vulnerability with a CVSSv3 score of 9.3. Successful exploitation by an unauthenticated, remote attacker could lead to unauthorised resource access or allow the attacker to crash the firewall, leading to a denial-of-service condition.

Remediation advice

Affected organisations are encouraged to review SonicWall advisory SNWLID-2024-0015 and apply the relevant updates.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 6 September 2024 12:20 pm