CVE-2024-40766

CRITICAL CISA KEV EPSS 96.4%
Published Aug 23, 20241y ago · Modified Jun 17, 20261w ago
9.8 CVSS 3.1
Critical
Find Similar
Published Aug 23, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Sep 9, 2024 1y ago
KEV Due Sep 30, 2024 638d overdue

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CVSS Details

Base Score
9.8
Exploitability
3.9
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

CISA Known Exploited Overdue 638d
Added
Sep 9, 2024
Due
Sep 30, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

EPSS Exploit Probability
96.4% percentile
Exploit & Patch Status
Actively Exploited (KEV)
No Patch Available

Weaknesses 1

CWE-284

Affected Products 55

VendorProductVersionRange
sonicwallsonicos* <5.9.2.14-13o
sonicwallsoho*any
sonicwallsonicos* <6.5.2.8-2n
sonicwallnssp_12400*any
sonicwallnssp_12800*any
sonicwallsm9800*any
sonicwallsonicos* <6.5.4.15.116n
sonicwallnsa_2650*any
sonicwallnsa_3600*any
sonicwallnsa_3650*any
sonicwallnsa_4600*any
sonicwallnsa_4650*any
sonicwallnsa_5600*any
sonicwallnsa_5650*any
sonicwallnsa_6600*any
sonicwallnsa_6650*any
sonicwallsm_9200*any
sonicwallsm_9250*any
sonicwallsm_9400*any
sonicwallsm_9450*any
sonicwallsm_9600*any
sonicwallsm_9650*any
sonicwallsoho_250*any
sonicwallsoho_250w*any
sonicwallsohow*any
sonicwalltz_300*any
sonicwalltz_300p*any
sonicwalltz_300w*any
sonicwalltz_350*any
sonicwalltz_350w*any
sonicwalltz_400*any
sonicwalltz_400w*any
sonicwalltz_500*any
sonicwalltz_500w*any
sonicwalltz_600*any
sonicwalltz_600p*any
sonicwallsonicos* ≤7.0.1-5035
sonicwallnsa_2700*any
sonicwallnsa_3700*any
sonicwallnsa_4700*any
sonicwallnsa_5700*any
sonicwallnsa_6700*any
sonicwallnssp_10700*any
sonicwallnssp_11700*any
sonicwallnssp_13700*any
sonicwalltz270*any
sonicwalltz270w*any
sonicwalltz370*any
sonicwalltz370w*any
sonicwalltz470*any
sonicwalltz470w*any
sonicwalltz570*any
sonicwalltz570p*any
sonicwalltz570w*any
sonicwalltz670*any

References 2

  • psirt.global.sonicwall.com https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
    Vendor Advisory
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-40766
    US Government Resource

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.