CVE-2024-40766
SonicWall SonicOS Improper Access Control Vulnerability
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
CRITICAL · CVSS 9.8
⚠ CISA KEV
EPSS 0.03535
Ransomware: known
Act now
- Listed on CISA KEV (known exploited in the wild)
- Linked to known ransomware campaigns
- SSVC exploitation status: active
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0