Vulnerability Intelligence Report
SonicWall SonicOS Improper Access Control Vulnerability
CVE-2024-40766
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.3
CRITICAL
Exploitability:3.9
Impact Score:4.8
EPSS Probability:18.18%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-284 ↗CWE-284 Improper Access Control
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SonicWall | SonicOS | 5.9.2.14-12o and older versions (affected), 6.5.4.14-109n and older versions (affected), 7.0.1-5035 and older versions (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SonicWall, Inc. · Vendor · USA |
| Reserved | 2024-07-10T15:58:49 |
| Published | 2024-08-23T06:19:07 |
| Patch Date | 2024-08-23 |
| Last Updated | 2026-09-21T20:25:59 |
Community Chatter & Buzz