First published: Fri Aug 23 2024(Updated: )
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL SonicOS | ||
All of | ||
SonicWALL SonicOS | <5.9.2.14-13o | |
SonicWall SOHO | ||
All of | ||
SonicWALL SonicOS | <6.5.2.8-2n | |
Any of | ||
SonicWall NSSP 12400 | ||
SonicWall NSSP 12800 | ||
SonicWall SuperMassive 9800 | ||
All of | ||
SonicWALL SonicOS | <6.5.4.15.116n | |
Any of | ||
SonicWall NSA 2650 | ||
SonicWall NSA 3600 | ||
SonicWall NSA 3650 Firmware | ||
SonicWall NSA 4600 | ||
SonicWall NSA 4650 Firmware | ||
SonicWall NSA 5600 | ||
SonicWall NSA 5650 | ||
SonicWall NSA 6600 | ||
SonicWall NSA 6650 | ||
SonicWall SM9200 | ||
SonicWall SM 9250 | ||
SonicWall SuperMassive 9400 | ||
SonicWall SM 9450 | ||
SonicWall SM 9600 | ||
SonicWall SM 9650 | ||
SonicWall SOHO 250W | ||
SonicWall SOHO 250W | ||
SonicWall SOHO | ||
SonicWall TZ300 Firmware | ||
SonicWall TZ300P Firmware | ||
SonicWall TZ300W Firmware | ||
SonicWall TZ350 Firmware | ||
SonicWall TZ350W Firmware | ||
SonicWall TZ400W Firmware | ||
SonicWall TZ400W Firmware | ||
SonicWall TZ500W | ||
SonicWall TZ500W | ||
SonicWall TZ600 Firmware | ||
SonicWall TZ600P | ||
All of | ||
SonicWALL SonicOS | <=7.0.1-5035 | |
Any of | ||
SonicWall NSA 2700 | ||
SonicWall NSA 3700 Firmware | ||
SonicWall NSA 4700 | ||
SonicWall NSA 5700 | ||
SonicWall NSA 6700 Firmware | ||
SonicWall NSSP 10700 Firmware | ||
SonicWall NSSP 11700 | ||
SonicWall NSSP 13700 | ||
SonicWall TZ270 | ||
SonicWall TZ270W Firmware | ||
SonicWall TZ370 | ||
SonicWall TZ370W Firmware | ||
SonicWall TZ470 Firmware | ||
SonicWall TZ470W Firmware | ||
SonicWall TZ570 Firmware | ||
SonicWall TZ570P Firmware | ||
SonicWall TZ570W Firmware | ||
SonicWall TZ670 Firmware |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40766 is classified as a critical severity vulnerability due to its potential to allow unauthorized access and cause service disruptions.
To fix CVE-2024-40766, update your SonicWall SonicOS to the latest version that addresses this vulnerability.
CVE-2024-40766 affects SonicWall Firewall Gen 5 and Gen 6 devices running vulnerable versions of SonicOS.
CVE-2024-40766 is an improper access control vulnerability that can lead to unauthorized resource access.
Yes, under specific conditions, CVE-2024-40766 can lead to a crash of the firewall.