SonicWall has issued an urgent security advisory regarding a critical vulnerability (CVE-2024-40766) affecting its firewall products . The company warns that this access control vulnerability is potentially being actively exploited, posing an immediate risk to users .
See also: SonicWall: Critical vulnerability in SonicOS

The vulnerability, with a CVSS score of 9.3 , affects SonicWall Firewall Gen 5 and Gen 6 appliances , as well as Gen 7 appliances with SonicOS versions 7.0.1-5035 and earlier .
If successfully exploited, it could lead to unauthorized access to resources and, under certain circumstances, cause the firewall to collapse.
The company strongly urges all customers to apply these patches immediately, as the vulnerability is believed to be actively exploited. Users can download the latest patches from mysonicwall.com.
SonicWall recommends implementing workarounds to minimize the potential impact for those who cannot immediately patch the vulnerability. These include limiting firewall management to trusted sources and disabling WAN firewall management from Internet. Similar precautions should be taken for SSLVPN.
See also: SonicWall: Thousands of firewalls are vulnerable to DoS and RCE attacks
Additionally, SonicWall advises customers using Gen5 and Gen6 firewalls and SSLVPN users with locally managed accounts to immediately update their passwords. Administrators should enable the “User must change password” option for each local account to enforce this critical security measure.

The company also recommends enabling Multi-Factor Authentication (MFA) for all SSLVPN users, using either TOTP or email-based OTP methods.
Given the critical nature of this vulnerability and its potential for exploitation, organizations using affected SonicWall products should treat it as a high-priority security issue. Prompt action to apply patches or implement recommended workarounds is critical to mitigating the risk of unauthorized access or system failures.
See also: LiteSpeed Cache Vulnerability: 6 million WordPress sites at risk
Access control vulnerabilities, such as the one from SonicWall, refer to weaknesses that allow unauthorized users to gain access to restricted areas of a system or application. These vulnerabilities can result from misconfigurations, improper permissions, or flaws in security protocols. Attackers could exploit these weaknesses to view, modify, or delete sensitive data, which can lead to serious consequences, including data breaches and loss of user trust. It is critical for organizations to implement strong access control mechanisms, conduct regular security audits, and provide training to employees to recognize and mitigate potential access control issues.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
