SonicWall SSLVPN access control flaw is now exploited in attacks

Share:

SonicWall is warning that a recently fixed access control flaw tracked as CVE-2024-40766 in SonicOS is now “potentially” exploited in attacks, urging admins to apply patches as soon as possible.

“This vulnerability is potentially being exploited in the wild. Please apply the patch as soon as possible for affected products. The latest patch builds are available for download on mysonicwall.com,” warns the updated SonicWall advisory.

CVE-2024-40766 is a critical (CVSS v3 score: 9.3) access control flaw impacting SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices.

The software vendor did not disclose much information about the flaw other than its potential for unauthorized resource access and ability to crash the firewall, thus eliminating network protections.

When SonicWall first disclosed the flaw on August 22, 2024, the flaw was only believed to be in the SonicWall SonicOS management access. With today’s update, the company is warning that CVE-2024-40766 also impacts the firewall’s SSLVPN feature.

Apply patches as soon as possible

The list of impacted products and versions, as well as the releases that address CVE-2024-40766, are summarized as follows:

  • SonicWall Gen 5 running SonicOS version 5.9.2.14-12o and older – fixed in SonicOS version 5.9.2.14-13o
  • SonicWall Gen 6 running SonicOS version 6.5.4.14-109n and older – fixed in 6.5.2.8-2n (for SM9800, NSsp 12400, NSsp 12800) and version 6.5.4.15-116n (for other Gen 6 Firewalls)
  • SonicWall Gen 7 running SonicOS version 7.0.1-5035 and older – not reproducible in 7.0.1-5035 and later.

The latest mitigation recommendations by SonicWall include:

  1. Limit firewall management to trusted sources and disable internet access to the WAN management portal if possible.
  2. Restrict SSLVPN access to trusted sources only and disable it entirely if not needed.
  3. For Gen 5 and Gen 6 devices, SSLVPN users with local accounts should update their passwords immediately and administrators should enable the “User must change password” option for local users.
  4. Enable multi-factor authentication (MFA) for all SSLVPN users using TOTP or email-based one-time passwords (OTPs). More information on how to configure this measure is available here.

While SonicWall has not shared how the flaw is being actively exploited, similar flaws have been used in the past to gain initial access to corporate networks.

Threat actors commonly target SonicWall as they are exposed to the internet to provide remote VPN access.

In March 2023, suspected Chinese hackers (UNC4540) targeted unpatched SonicWall Secure Mobile Access (SMA) devices to install custom malware that persisted through firmware upgrades.

BleepingComputer contacted SonicWall to learn more about how the flaw is being actively exploited in attacks, but a response was not immediately available.

Update 9/9 – According to an Arctic Wolf report, Akira ransomware is among the cybercriminals exploiting CVE-2024-40766 in attacks.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:23 pm, Jun 22, 2025
weather icon 25°C
L: 24° | H: 26°
scattered clouds
Humidity: 49 %
Pressure: 1013 mb
Wind: 15 mph WSW
Wind Gust: 19 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
24° | 26°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 4:00 pm
weather icon
21° | 24°°C 0 mm 0% 17 mph 47 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
21° | 21°°C 0 mm 0% 12 mph 32 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,150.11
-1.15%
Ethereum(ETH)
€1,976.75
-6.75%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.75
-5.46%
Solana(SOL)
€115.89
-6.07%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.135155
-4.58%
Shiba Inu(SHIB)
€0.000010
-5.08%
Pepe(PEPE)
€0.000008
-8.70%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top