First published: Thu Feb 08 2024(Updated: )
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This issue affects only firmware version SonicOS 7.1.1-7040.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
SonicWall NSA 2700 | ||
SonicWall NSA 3700 Firmware | ||
SonicWall NSA 4700 | ||
SonicWall NSA 5700 | ||
SonicWall NSA 6700 Firmware | ||
SonicWall NSSP 10700 Firmware | ||
SonicWall NSSP 11700 | ||
SonicWall NSSP 13700 | ||
SonicWall NSV 270 | ||
SonicWall NSV 470 Firmware | ||
SonicWall NSv 870 | ||
SonicWall TZ270 | ||
SonicWall TZ270W Firmware | ||
SonicWall TZ370 | ||
SonicWall TZ370W Firmware | ||
SonicWall TZ470 Firmware | ||
SonicWall TZ470W Firmware | ||
SonicWall TZ570 Firmware | ||
SonicWall TZ570P Firmware | ||
SonicWall TZ570W Firmware | ||
SonicWall TZ670 Firmware | ||
SonicWall SonicOS | =7.1.1-7040 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22394 is categorized as a high severity vulnerability due to its potential to allow remote unauthenticated access.
To fix CVE-2024-22394, upgrade to a patched version of SonicOS that addresses this vulnerability.
CVE-2024-22394 specifically affects SonicWall SonicOS firmware version 7.1.1-7040.
CVE-2024-22394 is an improper authentication vulnerability in the SSL-VPN feature of SonicWall SonicOS.
Yes, CVE-2024-22394 can be exploited remotely by attackers to bypass authentication under specific conditions.