← Back to CVE List
Vulnerability Intelligence Report
SonicWall SonicOS Improper Access Control Vulnerability

CVE-2024-40766

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.3
CRITICAL
Exploitability:3.9
Impact Score:4.8
EPSS Probability:18.18%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-284 ↗CWE-284 Improper Access Control

Affected Products & Versions

Vendor Product Affected Versions
SonicWall SonicOS 5.9.2.14-12o and older versions (affected), 6.5.4.14-109n and older versions (affected), 7.0.1-5035 and older versions (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
18.177%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySonicWall, Inc. · Vendor · USA
Reserved2024-07-10T15:58:49
Published2024-08-23T06:19:07
Patch Date2024-08-23
Last Updated2026-09-21T20:25:59

LINK COPIED TO CLIPBOARD