Vulnerability record · CVE-2024-53704 · published 9 January 2025
CVE-2024-53704: SonicWall SonicOS SSLVPN authentication bypass
Sonicwall · Sonicos
SonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, it exposes the SSLVPN service directly to unauthenticated compromise.
Description
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network bypass, CISA KEV listing with known ransomware use, and EPSS above 0.95 make this an urgent patch-first issue.
What it is
SonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, it exposes the SSLVPN service directly to unauthenticated compromise.
Impact
An attacker gains full unauthenticated access to the SSLVPN, with high impact to confidentiality, integrity and availability per the CVSS vector. That access can be used to reach internal networks and systems normally protected by the VPN.
Attack surface
Reachable over the network via the SSLVPN authentication mechanism (AV:N, AC:L, PR:N, UI:N). No authentication or user interaction is needed, so any internet-exposed SSLVPN interface is a candidate target.
Exploitation
Listed in CISA KEV (added 2025-02-18) with known ransomware campaign use, and EPSS 30-day probability is 0.95132 (99.86th percentile), indicating active exploitation. The vendor advisory and CISA KEV entry are the only references provided.
What to do
- Apply the SonicWall vendor fix per PSIRT advisory SNWLID-2025-0003; patch internet-facing SSLVPN immediately.
- If no patch can be applied, follow CISA KEV required action: apply vendor mitigations or discontinue use of the product.
- Restrict or disable SSLVPN access from the internet until patched, limiting exposure to trusted networks only.
- Enforce MFA and review SSLVPN accounts for unauthorized sessions or configuration changes.
- Monitor vendor and CISA guidance for updated mitigations given known ransomware use.
Detection
- Review SSLVPN authentication logs for successful logins without valid credential or MFA events.
- Hunt for anomalous SSLVPN session creation from unexpected source IPs or at unusual times.
- Check for post-authentication configuration changes, new local accounts, or VPN policy modifications.
- Correlate SSLVPN access with subsequent lateral movement or ransomware precursor activity on internal hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-53704 to the Known Exploited Vulnerabilities catalog on 18 February 2025 as "SonicWall SonicOS SSLVPN Improper Authentication Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-53704 | US Government Resource |
Track CVE-2024-53704 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-53704), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.