CVE-2024-53704

CRITICAL CISA KEV EPSS 99.9%
Published Jan 9, 20251y ago · Modified Jun 17, 20261w ago
9.8 CVSS 3.1
Critical
Find Similar
Published Jan 9, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
KEV Listed Feb 18, 2025 1y ago
KEV Due Mar 11, 2025 475d overdue

Description

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CVSS Details

Base Score
9.8
Exploitability
3.9
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

CISA Known Exploited Overdue 475d
Added
Feb 18, 2025
Due
Mar 11, 2025

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

EPSS Exploit Probability
99.9% percentile
Exploit & Patch Status
Actively Exploited (KEV)
No Patch Available

Weaknesses 1

CWE-287 Improper Authentication Authentication

Affected Products 26

VendorProductVersionRange
sonicwallsonicos*≥7.1.1-7040  –  ≤7.1.1-7058
sonicwallsonicos7.1.2-7019any
sonicwallnsa_2700*any
sonicwallnsa_3700*any
sonicwallnsa_4700*any
sonicwallnsa_5700*any
sonicwallnsa_6700*any
sonicwallnssp_10700*any
sonicwallnssp_11700*any
sonicwallnssp_13700*any
sonicwallnssp_15700*any
sonicwallnsv_270*any
sonicwallnsv_470*any
sonicwallnsv_870*any
sonicwalltz270*any
sonicwalltz270w*any
sonicwalltz370*any
sonicwalltz370w*any
sonicwalltz470*any
sonicwalltz470w*any
sonicwalltz570*any
sonicwalltz570p*any
sonicwalltz570w*any
sonicwalltz670*any
sonicwallsonicos8.0.0-8035any
sonicwalltz80*any

References 2

  • psirt.global.sonicwall.com https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003
    Vendor Advisory
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-53704
    US Government Resource

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.