First published: Fri Aug 23 2024(Updated: )
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS | ||
All of | ||
SonicWall SonicOS | <5.9.2.14-13o | |
SonicWALL SOHO | ||
All of | ||
SonicWall SonicOS | <6.5.2.8-2n | |
Any of | ||
Sonicwall Nssp 12400 | ||
Sonicwall Nssp 12800 | ||
Sonicwall Sm9800 | ||
All of | ||
SonicWall SonicOS | <6.5.4.15.116n | |
Any of | ||
Sonicwall Nsa 2650 | ||
Sonicwall Nsa 3600 | ||
Sonicwall Nsa 3650 | ||
Sonicwall Nsa 4600 | ||
Sonicwall Nsa 4650 | ||
Sonicwall Nsa 5600 | ||
Sonicwall Nsa 5650 | ||
Sonicwall Nsa 6600 | ||
Sonicwall Nsa 6650 | ||
Sonicwall Sm 9200 | ||
Sonicwall Sm 9250 | ||
Sonicwall Sm 9400 | ||
Sonicwall Sm 9450 | ||
Sonicwall Sm 9600 | ||
Sonicwall Sm 9650 | ||
Sonicwall Soho 250 | ||
Sonicwall Soho 250w | ||
Sonicwall Sohow | ||
Sonicwall Tz 300 | ||
Sonicwall Tz 300p | ||
Sonicwall Tz 300w | ||
Sonicwall Tz 350 | ||
Sonicwall Tz 350w | ||
Sonicwall Tz 400 | ||
Sonicwall Tz 400w | ||
Sonicwall Tz 500 | ||
Sonicwall Tz 500w | ||
Sonicwall Tz 600 | ||
Sonicwall Tz 600p | ||
All of | ||
SonicWall SonicOS | <=7.0.1-5035 | |
Any of | ||
Sonicwall Nsa 2700 | ||
Sonicwall Nsa 3700 | ||
Sonicwall Nsa 4700 | ||
Sonicwall Nsa 5700 | ||
Sonicwall Nsa 6700 | ||
Sonicwall Nssp 10700 | ||
Sonicwall Nssp 11700 | ||
Sonicwall Nssp 13700 | ||
Sonicwall Tz270 | ||
Sonicwall Tz270w | ||
Sonicwall Tz370 | ||
Sonicwall Tz370w | ||
Sonicwall Tz470 | ||
Sonicwall Tz470w | ||
Sonicwall Tz570 | ||
Sonicwall Tz570p | ||
Sonicwall Tz570w | ||
Sonicwall Tz670 |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.