← Vulnerability feed

Vulnerability record · CVE-2024-22394 · published 8 February 2024

CVE-2024-22394: Sonicwall sonicos improper authentication vulnerability

Sonicwall · Sonicos

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.

9.8 CVSS 3.1 Critical EPSS 0.75% · top 47.0% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
0.75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-22394 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-53704SonicWall SonicOS SSLVPN authentication bypassSonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a C…KEVEPSS 95%analysed9.8CVE-2024-40766SonicWall SonicOS improper access control in management accessSonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash …KEVEPSS 18%analysed9.8CVE-2020-5135SonicWall SonicOS buffer overflow in firewall request handlingSonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.…KEVEPSS 27%analysed9.8CVE-2025-40600Sonicwall sonicos vulnerabilityUse of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service d…EPSS 0.91%9.8CVE-2022-22274SonicOS HTTP request stack buffer overflowSonicOS and SonicOSv contain a stack-based buffer overflow reachable through an HTTP request. A remote unauthenticated attacker can trigger it to cra…EPSS 76%analysed9.8CVE-2019-12260Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…EPSS 23%9.8CVE-2019-12261Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…EPSS 9.0%9.8CVE-2019-12255VxWorks IPNET TCP urgent pointer integer underflow buffer overflowWind River VxWorks contains a buffer overflow in the TCP component of its IPNET network stack, triggered by a TCP Urgent Pointer value of 0 that caus…EPSS 75%analysed

Source: NIST National Vulnerability Database (record CVE-2024-22394), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.