← Vulnerability feed

Vulnerability record · CVE-2024-40766 · published 23 August 2024

CVE-2024-40766: SonicWall SonicOS improper access control in management access

Sonicwall · Sonicos

SonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash the firewall. It affects SonicWall Firewall Gen 5 and Gen 6 devices and Gen 7 devices running SonicOS 7.0.1-5035 and older. The flaw is remotely reachable without credentials or user interaction, making it a serious exposure for internet-facing management interfaces.

9.8 CVSS 3.1 Critical CISA KEV since 9 Sep 2024 Known ransomware use EPSS 18% · top 2.9% CWE-284 · Improper access control
9.8CVSS 3.1 base score
18%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
21 Sep 2026Last modified by NVD

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network reachability, KEV listing with known ransomware use and a near-term federal remediation deadline make this an urgent patch.

What it is

SonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash the firewall. It affects SonicWall Firewall Gen 5 and Gen 6 devices and Gen 7 devices running SonicOS 7.0.1-5035 and older. The flaw is remotely reachable without credentials or user interaction, making it a serious exposure for internet-facing management interfaces.

Impact

An unauthenticated attacker can gain unauthorized access to resources and, in specific conditions, cause the firewall to crash, disrupting network protection. The CVSS vector indicates high confidentiality, integrity and availability impact.

Attack surface

Reached over the network via the SonicOS management access interface (CVSS AV:N, PR:N, UI:N), so no authentication or user interaction is required. Devices with management access exposed to untrusted networks are the primary concern.

Exploitation

CISA added it to KEV on 2024-09-09 with a 2024-09-30 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is about 18.2% (97th percentile). The record does not state whether public exploit code exists.

What to do

  • Apply the SonicWall vendor fix for the affected SonicOS versions; check the SNWLID-2024-0015 advisory for the exact patched release.
  • If patching is not immediately possible, follow CISA's required action and vendor instructions, or discontinue use of the affected product.
  • Restrict management access to trusted internal networks and disable internet-facing administrative interfaces.
  • Enforce MFA and strong access controls on any remaining management access paths.
  • Monitor for and isolate affected Gen 5, Gen 6 and Gen 7 devices until they are confirmed patched.

Detection

  • Review SonicOS management access logs for unexpected or unauthenticated administrative sessions and configuration changes.
  • Alert on firewall crash or unexpected reboot events on affected SonicWall devices.
  • Hunt for anomalous inbound traffic to management interfaces from untrusted sources.
  • Correlate firewall telemetry with ransomware precursor activity given the KEV ransomware flag.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-40766 to the Known Exploited Vulnerabilities catalog on 9 September 2024 as "SonicWall SonicOS Improper Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 30 September 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-40766 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-53704SonicWall SonicOS SSLVPN authentication bypassSonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a C…KEVEPSS 95%analysed9.8CVE-2020-5135SonicWall SonicOS buffer overflow in firewall request handlingSonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.…KEVEPSS 27%analysed9.8CVE-2025-40600Sonicwall sonicos vulnerabilityUse of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service d…EPSS 0.91%9.8CVE-2024-22394Sonicwall sonicos improper authentication vulnerabilityAn improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …EPSS 0.75%9.8CVE-2022-22274SonicOS HTTP request stack buffer overflowSonicOS and SonicOSv contain a stack-based buffer overflow reachable through an HTTP request. A remote unauthenticated attacker can trigger it to cra…EPSS 76%analysed9.8CVE-2019-12260Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…EPSS 23%9.8CVE-2019-12261Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…EPSS 9.0%9.8CVE-2019-12255VxWorks IPNET TCP urgent pointer integer underflow buffer overflowWind River VxWorks contains a buffer overflow in the TCP component of its IPNET network stack, triggered by a TCP Urgent Pointer value of 0 that caus…EPSS 75%analysed

Source: NIST National Vulnerability Database (record CVE-2024-40766), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.