ZDI-25-012: SonicWALL NSv Authentication Bypass Vulnerability
Published Jan 9, 2025
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of SonicWALL NSv. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-53704.
Affected Software
1 affected component
SonicWALL NSv
Event History
Jan 9, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-012?
The severity of ZDI-25-012 is rated at 9.8 on the CVSS scale, indicating critical vulnerability.
2
How do I fix ZDI-25-012?
To address ZDI-25-012, install the latest security updates provided by SonicWALL for the NSv product.
3
What type of attack does ZDI-25-012 allow?
ZDI-25-012 allows remote attackers to bypass authentication on affected installations of SonicWALL NSv.
4
Is authentication required to exploit ZDI-25-012?
No, authentication is not required to exploit the vulnerability identified as ZDI-25-012.
5
What CVE is associated with ZDI-25-012?
The CVE associated with ZDI-25-012 is CVE-2024-53704.