CVE-2024-40766: SonicWall SonicOS Improper Access Control Vulnerability
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Other sources
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If vendor mitigations are unavailable, discontinue use of affected devices: SonicWall Firewall Gen 5 and Gen 6 devices, and Gen 7 devices running SonicOS 7.0.1-5035 and older.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40766?
CVE-2024-40766 is classified as a critical severity vulnerability due to its potential to allow unauthorized access and cause service disruptions.
How do I fix CVE-2024-40766?
To fix CVE-2024-40766, update your SonicWall SonicOS to the latest version that addresses this vulnerability.
Which SonicWall devices are affected by CVE-2024-40766?
CVE-2024-40766 affects SonicWall Firewall Gen 5 and Gen 6 devices running vulnerable versions of SonicOS.
What type of vulnerability is CVE-2024-40766?
CVE-2024-40766 is an improper access control vulnerability that can lead to unauthorized resource access.
Can CVE-2024-40766 cause a firewall to crash?
Yes, under specific conditions, CVE-2024-40766 can lead to a crash of the firewall.