Vulnerability record · CVE-2024-40766 · published 23 August 2024
CVE-2024-40766: SonicWall SonicOS improper access control in management access
Sonicwall · Sonicos
SonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash the firewall. It affects SonicWall Firewall Gen 5 and Gen 6 devices and Gen 7 devices running SonicOS 7.0.1-5035 and older. The flaw is remotely reachable without credentials or user interaction, making it a serious exposure for internet-facing management interfaces.
Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network reachability, KEV listing with known ransomware use and a near-term federal remediation deadline make this an urgent patch.
What it is
SonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash the firewall. It affects SonicWall Firewall Gen 5 and Gen 6 devices and Gen 7 devices running SonicOS 7.0.1-5035 and older. The flaw is remotely reachable without credentials or user interaction, making it a serious exposure for internet-facing management interfaces.
Impact
An unauthenticated attacker can gain unauthorized access to resources and, in specific conditions, cause the firewall to crash, disrupting network protection. The CVSS vector indicates high confidentiality, integrity and availability impact.
Attack surface
Reached over the network via the SonicOS management access interface (CVSS AV:N, PR:N, UI:N), so no authentication or user interaction is required. Devices with management access exposed to untrusted networks are the primary concern.
Exploitation
CISA added it to KEV on 2024-09-09 with a 2024-09-30 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is about 18.2% (97th percentile). The record does not state whether public exploit code exists.
What to do
- Apply the SonicWall vendor fix for the affected SonicOS versions; check the SNWLID-2024-0015 advisory for the exact patched release.
- If patching is not immediately possible, follow CISA's required action and vendor instructions, or discontinue use of the affected product.
- Restrict management access to trusted internal networks and disable internet-facing administrative interfaces.
- Enforce MFA and strong access controls on any remaining management access paths.
- Monitor for and isolate affected Gen 5, Gen 6 and Gen 7 devices until they are confirmed patched.
Detection
- Review SonicOS management access logs for unexpected or unauthenticated administrative sessions and configuration changes.
- Alert on firewall crash or unexpected reboot events on affected SonicWall devices.
- Hunt for anomalous inbound traffic to management interfaces from untrusted sources.
- Correlate firewall telemetry with ransomware precursor activity given the KEV ransomware flag.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-40766 to the Known Exploited Vulnerabilities catalog on 9 September 2024 as "SonicWall SonicOS Improper Access Control Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 30 September 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-40766 | US Government Resource |
Track CVE-2024-40766 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-40766), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.