• News/
  • https://www.theregister.com/2025/02/14/sonicwall_firewalls_under_attack_patch/

SonicWall firewalls under attack. Patch now

The Register
·
Jessica Lyons
·
Published Feb 14, 2025
·
Updated

updated Miscreants are actively abusing a high-severity authentication bypass bug in unpatched internet-facing SonicWall firewalls following the public release of proof-of-concept exploit code. The vulnerability, tracked as CVE-2024-53704, is a flaw in the SSL VPN authentication mechanism in SonicOS, the operating system that SonicWall firewalls use. If exploited, it allows remote attackers to bypass authentication on vulnerable SonicOS equipment, hijack the devices' active SSL VPN sessions, and gain unauthorized access to affected networks. "Shortly after the proof-of-concept was made public, Arctic Wolf began observing exploitation attempts of this vulnerability in the threat landscape," the threat monitoring and detection outfit warned Thursday. SonicWall first disclosed CVE-2024-53704 in early January. The security hole affects multiple Gen 7 and TZ80 SonicWall firewalls. The good news is upgrading to the latest version of SonicOS will plug the hole. Given that attackers ranging from suspected Chinese spies to ransomware criminals have a history of exploiting buggy SonicWall devices, you'd hope users patched this hole immediately. Not everyone got the memo, it appears. On January 30, Bishop Fox researchers said they were able exploit the flaw in unpatched firewalls and called the attack "trivial." SonicWall echoed this call to action in an updated security advisory, and said "customers must immediately update." If for whatever reason you can't update to a fixed firmware v...

Read full article

Affected Software

6 affected components
SonicWall Gen 7
SonicWall TZ80
SonicWall SonicOS
SonicWall SonicOS
SonicWall Gen 7 firewalls
SonicWall TZ80 firewalls

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity authentication bypass vulnerability in unpatched SonicWall firewalls and the immediate need for users to apply a security patch.

2

What security implications are discussed?

The article highlights that miscreants are actively exploiting the authentication bypass bug, which poses a significant risk to internet-facing SonicWall firewalls.

3

What products or software are affected?

The affected products include SonicWall Gen 7 firewalls, SonicWall TZ80 firewalls, and SonicWall SonicOS.

4

What is the CVE identifier associated with this vulnerability?

The vulnerability is tracked as CVE-2024-53704.

5

What action should users of SonicWall firewalls take?

Users are urged to update their firewalls by applying the newly available security patch to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203