PT-2024-5748 · Sonicwall · Sonicos

CVE-2024-40766

·

Published

2024-08-22

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicWall Firewall Gen 5 (affected versions not specified) SonicWall Firewall Gen 6 (affected versions not specified) SonicWall SonicOS versions prior to 7.0.1-5035
Description An improper access control issue exists in the SonicWall SonicOS management access, which can allow remote attackers to gain unauthorized access to resources or cause the firewall to crash. This flaw has been actively exploited by the Akira ransomware group to gain initial access to networks, sometimes bypassing multi-factor authentication (MFA) by utilizing credentials migrated from older devices or potentially compromising OTP seeds. Once inside, attackers have been observed performing network scanning and deploying ransomware, often within hours of the initial breach. In some instances, the vulnerability was used to facilitate lateral movement into virtual machine environments, including Nutanix AHV, VMware ESXi, and Hyper-V.
Recommendations For SonicWall Firewall Gen 5 and Gen 6, update firmware to a version that addresses the improper access control issue. For SonicOS versions prior to 7.0.1-5035, update firmware to version 7.3.0 to obtain enhanced protections against brute-force attacks and improved MFA controls. Reset all local user account passwords for any accounts with SSLVPN access, particularly those carried over during migration from Gen 6 to Gen 7. Enable Botnet Protection and Geo-IP Filtering. Remove all unused or inactive local user accounts. Enforce strong password policies and MFA/TOTP configurations. Restrict Virtual Office Portal access to the internal network. As a temporary mitigation, disable SNMP traps before upgrading to version 7.3.0 to prevent potential firewall crashes.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06461
CVE-2024-40766

Affected Products

Sonicos