All CVEs View on NVD
CVE-2024-40766
CRITICAL9.8
CISA KEV
Published 2024-08-23 · Updated 2026-09-21 · Source PSIRT@sonicwall.com
Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-284
CISA Known-Exploited Vulnerability
Product: SonicWall — SonicOS
Name: SonicWall SonicOS Improper Access Control Vulnerability
Date added: 2024-09-09 · Due: 2024-09-30
USED IN RANSOMWARE
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

