CVE-2024-40766

CRITICAL CISA KEV
Published Aug 23, 2024 Modified Oct 31, 2025 CWE-284

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild.

Added: Sep 9, 2024 Remediation due: Sep 30, 2024 Known ransomware use

Weakness Type (CWE)

CWE-284 CWE-284

Affected Products

Vendor Product
sonicwall sonicos
sonicwall soho
sonicwall sonicos
sonicwall nssp_12400
sonicwall nssp_12800
sonicwall sm9800
sonicwall sonicos
sonicwall nsa_2650
sonicwall nsa_3600
sonicwall nsa_3650
sonicwall nsa_4600
sonicwall nsa_4650
sonicwall nsa_5600
sonicwall nsa_5650
sonicwall nsa_6600
sonicwall nsa_6650
sonicwall sm_9200
sonicwall sm_9250
sonicwall sm_9400
sonicwall sm_9450
sonicwall sm_9600
sonicwall sm_9650
sonicwall soho_250
sonicwall soho_250w
sonicwall sohow
sonicwall tz_300
sonicwall tz_300p
sonicwall tz_300w
sonicwall tz_350
sonicwall tz_350w
sonicwall tz_400
sonicwall tz_400w
sonicwall tz_500
sonicwall tz_500w
sonicwall tz_600
sonicwall tz_600p
sonicwall sonicos
sonicwall nsa_2700
sonicwall nsa_3700
sonicwall nsa_4700
sonicwall nsa_5700
sonicwall nsa_6700
sonicwall nssp_10700
sonicwall nssp_11700
sonicwall nssp_13700
sonicwall tz270
sonicwall tz270w
sonicwall tz370
sonicwall tz370w
sonicwall tz470
sonicwall tz470w
sonicwall tz570
sonicwall tz570p
sonicwall tz570w
sonicwall tz670

References

Frequently Asked Questions

What is CVE-2024-40766? +
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. It has a CVSS v3.1 base score of 9.8 (CRITICAL). This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
How severe is CVE-2024-40766? +
CVE-2024-40766 has a CVSS v3.1 score of 9.8 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2024-40766? +
CVE-2024-40766 affects products from sonicwall, specifically: nsa_2650, nsa_2700, nsa_3600, nsa_3650, nsa_3700, nsa_4600, nsa_4650, nsa_4700, nsa_5600, nsa_5650, nsa_5700, nsa_6600, nsa_6650, nsa_6700, nssp_10700, nssp_11700, nssp_12400, nssp_12800, nssp_13700, sm9800, sm_9200, sm_9250, sm_9400, sm_9450, sm_9600, sm_9650, soho, soho_250, soho_250w, sohow, sonicos, tz270, tz270w, tz370, tz370w, tz470, tz470w, tz570, tz570p, tz570w, tz670, tz_300, tz_300p, tz_300w, tz_350, tz_350w, tz_400, tz_400w, tz_500, tz_500w, tz_600, tz_600p. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-40766? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-40766 — free, no signup required.

Start Free Scan