CVE-2024-40763: Buffer Overflow
Published Dec 5, 2024
·Updated
Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow and potentially lead to code execution.
Affected Software
11 affected components
SonicWall SMA100 SSLVPN
All of the following
SonicWall Sma 200 Firmware<10.2.1.14-75sv
SonicWall SMA 200
All of the following
SonicWall Sma 210 Firmware<10.2.1.14-75sv
SonicWall Sma 210
All of the following
SonicWall Sma 400 Firmware<10.2.1.14-75sv
SonicWall Sma 400
All of the following
SonicWall Sma 410 Firmware<10.2.1.14-75sv
SonicWall Sma 410
All of the following
SonicWall Sma 500v Firmware<10.2.1.14-75sv
SonicWall Sma 500v
Event History
Dec 5, 2024
CVE Published
via MITRE·01:39 PM
Data Sourced
via MITRE·01:39 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-40763?
CVE-2024-40763 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-40763?
To fix CVE-2024-40763, update the SonicWall SMA100 SSLVPN to the latest patched version provided by SonicWall.
3
What type of vulnerability is CVE-2024-40763?
CVE-2024-40763 is a heap-based buffer overflow vulnerability.
4
Who can exploit CVE-2024-40763?
Remote authenticated attackers can exploit CVE-2024-40763 to cause a heap-based buffer overflow.
5
What could be the impact of exploiting CVE-2024-40763?
Exploitation of CVE-2024-40763 could lead to remote code execution on the affected system.