CVE-2024-40766 - SonicWall SonicOS Improper Access Control Vulnerability
Project:SonicWall
Product:SonicOS
Date Added:2024-09-09Due Date:2024-09-30
Vulnerability Name
SonicWall SonicOS Improper Access Control Vulnerability
Description
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
https://nvd.nist.gov/vuln/detail/CVE-2024-40766
Related News Articles
SonicWall finds no SSLVPN zero-day, links ransomware attacks to 2024 flawAugust 7, 2025
SonicWall Confirms Patched Vulnerability Behind Recent VPN Attacks, Not a Zero-DayAugust 7, 2025
SonicWall: Attackers did not exploit zero-day vulnerability to compromise Gen 7 firewallsAugust 7, 2025
5,000+ SonicWall firewalls still open to attack (CVE-2024-53704)January 27, 2025
New Ymir Ransomware Exploits Memory for Stealthy Attacks; Targets Corporate NetworksNovember 12, 2024