CRITICAL · 9.8

CVE-2024-40766

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the fir...

Vulnerability Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SonicwallSonicos< 5.9.2.14-13o
SonicwallSoho-
SonicwallNssp 12400-
SonicwallNssp 12800-
SonicwallSm9800-
SonicwallNsa 2650-
SonicwallNsa 3600-
SonicwallNsa 3650-
SonicwallNsa 4600-
SonicwallNsa 4650-
SonicwallNsa 5600-
SonicwallNsa 5650-
SonicwallNsa 6600-
SonicwallNsa 6650-
SonicwallSm 9200-
SonicwallSm 9250-
SonicwallSm 9400-
SonicwallSm 9450-
SonicwallSm 9600-
SonicwallSm 9650-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-40766?

CVE-2024-40766 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the fir...

How severe is CVE-2024-40766?

CVE-2024-40766 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2024-40766?

Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Sonicos, Sonicwall Soho, Sonicwall Nssp 12400, Sonicwall Nssp 12800, Sonicwall Sm9800.