CVE-2024-40764

HIGH EPSS 48.5%
Published Jul 18, 20241y ago · Modified Jun 17, 20261w ago
7.5 CVSS 3.1
High
Find Similar
Published Jul 18, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

CVSS Details

Base Score
7.5
Exploitability
3.9
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
48.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 2

CWE-122
CWE-787 Out-of-bounds Write Memory Safety

Affected Products 34

VendorProductVersionRange
sonicwallsonicos* <6.5.4.v-21s-rc2457
sonicwallnsv10*any
sonicwallnsv100*any
sonicwallnsv1600*any
sonicwallnsv200*any
sonicwallnsv25*any
sonicwallnsv300*any
sonicwallnsv400*any
sonicwallnsv50*any
sonicwallnsv800*any
sonicwallsonicos* <7.0.1-5161
sonicwallsonicos*≥7.1.1-7040  –  <7.1.1-7058
sonicwallnsa_2700*any
sonicwallnsa_3700*any
sonicwallnsa_4700*any
sonicwallnsa_5700*any
sonicwallnsa_6700*any
sonicwallnssp_10700*any
sonicwallnssp_11700*any
sonicwallnssp_13700*any
sonicwallnssp_15700*any
sonicwallnsv_270*any
sonicwallnsv_470*any
sonicwallnsv_870*any
sonicwalltz270*any
sonicwalltz270w*any
sonicwalltz370*any
sonicwalltz370w*any
sonicwalltz470*any
sonicwalltz470w*any
sonicwalltz570*any
sonicwalltz570p*any
sonicwalltz570w*any
sonicwalltz670*any

References 1

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.