First published: Thu Jan 09 2025(Updated: )
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS SSL VPN NAC Agent |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40765 is classified as a high severity vulnerability due to its potential for Denial of Service and arbitrary code execution.
To fix CVE-2024-40765, you should update SonicWall SonicOS to the latest patched version released by SonicWall.
CVE-2024-40765 is an integer-based buffer overflow vulnerability affecting the IPSec implementation in SonicOS.
CVE-2024-40765 affects users of SonicWall SonicOS that utilize IPSec under specific conditions.
Yes, CVE-2024-40765 can be exploited remotely by an attacker sending a specially crafted IKEv2 payload.