• News/
  • https://www.bleepingcomputer.com/news/security/sonicwall-firewall-bug-targeted-in-attacks-after-poc-exploit-release/

SonicWall firewall bug targeted in attacks after PoC exploit release

BleepingComputer
·
Sergiu Gatlan
·
Published Feb 14, 2025
·
Updated

Attackers are now targeting an authentication bypass vulnerability affecting SonicWall firewalls shortly after the release of proof-of-concept (PoC) exploit code. This security flaw (CVE-2024-53704), tagged by CISA as critical severity and found in the SSLVPN authentication mechanism, impacts SonicOS versions 7.1.x (up to 7.1.1-7058), 7.1.2-7019, and 8.0.0-8035, used by multiple models of Gen 6 and Gen 7 firewalls and SOHO series devices. Successful exploitation enables remote attackers to hijack active SSL VPN sessions without authentication, which grants them unauthorized access to targets' networks. SonicWall urged customers to immediately upgrade their firewalls' SonicOS firmware to prevent exploitation in an email sent before disclosing the vulnerability publicly and releasing security updates on January 7. The company also shared mitigation measures for admins who couldn't immediately secure their devices, including limiting access to trusted sources and restricting access from the Internet entirely if not needed. On Thursday, cybersecurity company Arctic Wolf said they started detecting exploitation attempts targeting this vulnerability in attacks "shortly after the PoC was made public," confirming SonicWall's fears regarding the vulnerability's increased exploitation potential. "The released PoC exploit allows an unauthenticated threat actor to bypass MFA, disclose private information, and interrupt running VPN sessions," Arctic Wolf stated. "Given the ease of exploi...

Read full article

Affected Software

6 affected components
SonicWall SonicOS=7.1.x
SonicWall SonicOS=7.1.2-7019
SonicWall SonicOS=8.0.0-8035
SonicWall SonicOS=7.1.x
SonicWall SonicOS=7.1.2-7019
SonicWall SonicOS=8.0.0-8035
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerability is being reported in the article?

The article reports on an authentication bypass vulnerability (CVE-2024-53704) affecting SonicWall firewalls.

2

What are the security implications of this vulnerability?

Attackers are actively exploiting this vulnerability, posing significant risks to systems using affected SonicWall products.

3

Which versions of SonicWall SonicOS are affected?

The affected versions include SonicOS 7.1.x, 7.1.2-7019, and 8.0.0-8035.

4

What actions should users of affected SonicWall products take?

Users should promptly apply any available patches or updates to mitigate the vulnerabilities.

5

Who has identified the vulnerability as critical?

The vulnerability has been tagged as critical by CISA, indicating its severity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203