CVE-2024-40766

CRITICAL(9.8)KEVRansomwareElevated Risk

SonicWall SonicOS Improper Access Control Vulnerability

Description

CVE-2024-40766 is a critical-severity improper access control vulnerability in SonicWall SonicOS that affects Gen 5, Gen 6, and Gen 7 firewall devices running SonicOS 7.0.1-5035 and older. The flaw can lead to unauthorized access to resources and, under specific conditions, cause the firewall to crash — effectively disabling network security for the entire protected environment. With an EPSS score of 3.5% (87.4th percentile) and a perfect CVSS score of 9.8, this vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of September 30, 2024. Critically, this vulnerability has confirmed associations with ransomware campaigns, making immediate remediation essential.

KEV Information

Vendor
SonicWall
Product
SonicOS
Date Added
September 9, 2024
Due Date
September 30, 2024
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
sonicwallsonicos< 5.9.2.14-13o; < 6.5.2.8-2n; < 6.5.4.15.116n; <= 7.0.1-5035

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.3
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

References

Weakness Type

Improper Access Control

Although no formal CWE has been assigned to CVE-2024-40766, the vulnerability is classified as an improper access control flaw in the SonicOS management interface. This class of weakness occurs when a system fails to properly restrict access to sensitive resources or administrative functions, allowing unauthorized users to perform actions that should require authentication or elevated permissions. In the context of SonicWall firewalls, this means an unauthenticated remote attacker can potentially access management functions or resources that should be restricted to authorized administrators only. Improper access control in network security appliances is exceptionally dangerous because these devices serve as the primary security boundary for the networks they protect.

Learn more: CWE-284: Improper Access Control

Impact Analysis

The CVSS v3.1 base score of 9.8 (Critical) is nearly the maximum possible score, reflecting a vulnerability with catastrophic potential. Confidentiality (C:H), integrity (I:H), and availability (A:H) are all fully compromised, and critically, the attack requires no authentication (PR:N), no user interaction (UI:N), and has low attack complexity (AC:L) over the network. This combination means any attacker with network access to the SonicWall management interface can fully compromise the device without credentials.

From a business perspective, SonicWall firewalls are perimeter security devices that protect entire network segments. A compromised firewall grants an attacker the ability to intercept and modify all network traffic passing through the device, disable security rules to allow malicious traffic, create VPN tunnels for persistent access, and pivot into the internal network. The firewall crash condition described in the advisory is equally concerning — a denial of service against the firewall effectively removes all network security controls, leaving the protected network exposed. The EPSS score of 3.5% at the 87.4th percentile indicates significant exploitation activity. This vulnerability has a confirmed "Known" ransomware association in the KEV catalog, meaning ransomware operators are actively leveraging this flaw to gain initial access to victim networks.

Exploit Maturity

CVE-2024-40766 has been confirmed as actively exploited in the wild with a known association with ransomware campaigns, earning its placement in CISA's Known Exploited Vulnerabilities (KEV) catalog with a mandatory remediation deadline of September 30, 2024. The "Known" ransomware designation is the most severe classification in the KEV catalog, indicating that ransomware groups are actively using this vulnerability as part of their attack chains. The EPSS probability of 3.5% at the 87.4th percentile confirms above-average exploitation activity in the broader threat landscape.

SonicWall published an official security advisory (SNWLID-2024-0015) acknowledging the vulnerability and providing firmware updates. The combination of a 9.8 CVSS score, no authentication requirement, confirmed active exploitation, and known ransomware usage makes this one of the most dangerous vulnerabilities disclosed in 2024 for organizations running SonicWall firewalls. Security teams should treat this as an emergency patching event, particularly for any SonicWall devices with management interfaces accessible from the internet.

Remediation

  1. Update SonicOS firmware immediately — Apply the patched firmware versions specified in the SonicWall security advisory (SNWLID-2024-0015). For Gen 5 devices, upgrade to SonicOS 5.9.2.14-13o or later. For Gen 6 devices, upgrade to 6.5.2.8-2n or 6.5.4.15.116n or later. For Gen 7 devices, upgrade to a version newer than 7.0.1-5035.
  2. Restrict management interface access — Immediately limit access to the SonicWall management interface to trusted IP addresses only. Disable WAN-facing management access entirely if not required. Use SSLVPN or a dedicated management network for remote administration.
  3. Enable multi-factor authentication — Configure MFA for all administrative accounts on SonicWall devices. Additionally, generate new administrator passwords, as the access control flaw may have exposed existing credentials.
  4. Conduct compromise assessment — Review firewall logs for signs of unauthorized access, unusual configuration changes, new VPN accounts, or unexpected traffic patterns. Check for newly created administrator accounts or modified access rules that could indicate prior exploitation.
  5. Implement network monitoring — Deploy intrusion detection systems to monitor traffic to and from SonicWall management interfaces. Alert on connection attempts from unexpected sources and any anomalous firewall behavior, including unexpected reboots that may indicate crash exploitation attempts.

Technical Details

The CVSS v3.1 vector for CVE-2024-40766 is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, yielding a critical base score of 9.8. Attack Vector (AV:N) confirms remote exploitation over the network. Attack Complexity (AC:L) indicates straightforward exploitation without special conditions. Privileges Required (PR:N) is the most concerning metric — no authentication whatsoever is needed. User Interaction (UI:N) confirms no human involvement is required. Scope (S:U) limits the directly affected component, though in practice, compromising a firewall has cascading effects across the entire protected network. Confidentiality (C:H), Integrity (I:H), and Availability (A:H) reflect total compromise of the device.

The vulnerability resides in the SonicOS management access control mechanism. The improper access control flaw allows unauthenticated attackers to reach administrative resources through the management interface without providing valid credentials. The advisory notes two distinct impacts: unauthorized resource access and a denial-of-service condition where the firewall crashes under specific conditions. The affected device range is broad — Gen 5, Gen 6, and Gen 7 devices are all vulnerable, with Gen 7 specifically affected when running SonicOS 7.0.1-5035 or older. The attack surface is any network path that can reach the SonicOS management interface, including HTTPS management, SSH management, or SSLVPN portals. Organizations that expose these interfaces to the internet face the highest risk, but internal network attackers can also exploit this vulnerability.

Frequently Asked Questions

What is CVE-2024-40766?

CVE-2024-40766 is a critical improper access control vulnerability in SonicWall SonicOS that allows unauthenticated remote attackers to access restricted resources on the firewall and potentially crash the device. With a CVSS score of 9.8, it requires no credentials and no user interaction to exploit, making it one of the most severe firewall vulnerabilities disclosed in 2024.

Which SonicWall devices are affected?

All SonicWall Gen 5, Gen 6, and Gen 7 firewall devices are affected. Gen 5 devices running SonicOS below 5.9.2.14-13o, Gen 6 devices below 6.5.2.8-2n or 6.5.4.15.116n, and Gen 7 devices running SonicOS 7.0.1-5035 or older are vulnerable. Organizations should consult the SonicWall advisory for their specific model's patched firmware version.

Is CVE-2024-40766 being used in ransomware attacks?

Yes. CISA's KEV catalog lists this vulnerability with a "Known" ransomware association, confirming that ransomware groups are actively exploiting it to gain initial access to victim networks. This makes immediate patching and management interface hardening critically important.

What should I do if I cannot patch immediately?

As an interim mitigation, immediately restrict access to the SonicWall management interface by limiting it to trusted IP addresses only and disabling WAN-facing management access. Enable MFA for all admin accounts, monitor logs for unauthorized access attempts, and plan for emergency patching at the earliest possible opportunity.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score18.18%
EPSS Percentile97.0%

Dates

PublishedAugust 23, 2024
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.