← Vulnerability feed

Vulnerability record · CVE-2024-53704 · published 9 January 2025

CVE-2024-53704: SonicWall SonicOS SSLVPN authentication bypass

Sonicwall · Sonicos

SonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, it exposes the SSLVPN service directly to unauthenticated compromise.

9.8 CVSS 3.1 Critical CISA KEV since 18 Feb 2025 Known ransomware use EPSS 95% · top 0.1% CWE-287 · Improper authentication
9.8CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
4 Aug 2026Last modified by NVD

Description

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network bypass, CISA KEV listing with known ransomware use, and EPSS above 0.95 make this an urgent patch-first issue.

What it is

SonicOS SSLVPN authentication contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication entirely. With a CVSS 3.1 score of 9.8 and no privileges or user interaction required, it exposes the SSLVPN service directly to unauthenticated compromise.

Impact

An attacker gains full unauthenticated access to the SSLVPN, with high impact to confidentiality, integrity and availability per the CVSS vector. That access can be used to reach internal networks and systems normally protected by the VPN.

Attack surface

Reachable over the network via the SSLVPN authentication mechanism (AV:N, AC:L, PR:N, UI:N). No authentication or user interaction is needed, so any internet-exposed SSLVPN interface is a candidate target.

Exploitation

Listed in CISA KEV (added 2025-02-18) with known ransomware campaign use, and EPSS 30-day probability is 0.95132 (99.86th percentile), indicating active exploitation. The vendor advisory and CISA KEV entry are the only references provided.

What to do

  • Apply the SonicWall vendor fix per PSIRT advisory SNWLID-2025-0003; patch internet-facing SSLVPN immediately.
  • If no patch can be applied, follow CISA KEV required action: apply vendor mitigations or discontinue use of the product.
  • Restrict or disable SSLVPN access from the internet until patched, limiting exposure to trusted networks only.
  • Enforce MFA and review SSLVPN accounts for unauthorized sessions or configuration changes.
  • Monitor vendor and CISA guidance for updated mitigations given known ransomware use.

Detection

  • Review SSLVPN authentication logs for successful logins without valid credential or MFA events.
  • Hunt for anomalous SSLVPN session creation from unexpected source IPs or at unusual times.
  • Check for post-authentication configuration changes, new local accounts, or VPN policy modifications.
  • Correlate SSLVPN access with subsequent lateral movement or ransomware precursor activity on internal hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-53704 to the Known Exploited Vulnerabilities catalog on 18 February 2025 as "SonicWall SonicOS SSLVPN Improper Authentication Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 11 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-53704 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40766SonicWall SonicOS improper access control in management accessSonicOS management access contains an improper access control flaw that can allow unauthorized resource access and, under specific conditions, crash …KEVEPSS 18%analysed9.8CVE-2020-5135SonicWall SonicOS buffer overflow in firewall request handlingSonicOS contains a classic buffer overflow (CWE-120) reachable by sending a malicious request to the firewall. It affects SonicOS Gen 6 versions 6.5.…KEVEPSS 27%analysed9.8CVE-2025-40600Sonicwall sonicos vulnerabilityUse of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service d…EPSS 0.91%9.8CVE-2024-22394Sonicwall sonicos improper authentication vulnerabilityAn improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …EPSS 0.75%9.8CVE-2022-22274SonicOS HTTP request stack buffer overflowSonicOS and SonicOSv contain a stack-based buffer overflow reachable through an HTTP request. A remote unauthenticated attacker can trigger it to cra…EPSS 76%analysed9.8CVE-2019-12260Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer…EPSS 23%9.8CVE-2019-12261Windriver vxworks classic buffer overflow vulnerabilityWind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urg…EPSS 9.0%9.8CVE-2019-12255VxWorks IPNET TCP urgent pointer integer underflow buffer overflowWind River VxWorks contains a buffer overflow in the TCP component of its IPNET network stack, triggered by a TCP Urgent Pointer value of 0 that caus…EPSS 75%analysed

Source: NIST National Vulnerability Database (record CVE-2024-53704), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.