Security researchers at Bishop Fox have published details about the exploitation of the SonicWall CVE-2024-53704 vulnerability, which allows mechanism authentication in some versions of the SonicOS SSLVPN.

The researchers say there is a high risk of exploitation and urge administrators to upgrade the firmware of their SonicOS firewalls to address the problem.
" We have identified a firewall vulnerability that compromises customers with SSL VPN or SSH management enabled and should be mitigated immediately by upgrading to the latest firmware ," SonicWall warned in an email sent to customers.
See also: Ivanti patches vulnerabilities in ICS, IPS and CSA products
The vulnerability allows a remote attacker to actively compromise unauthenticated SSL VPN sessions, gaining unauthorized access to the victim's.
On January 22, researchers at Bishop Fox announced that they had developed an exploit for CVE-2024-53704 . After giving system administrators some time to apply available patches , Bishop Fox published the full exploit details on Monday
The exploit works by sending a specially crafted session cookie, containing an encoded string with null bytes, to the SSL VPN authentication endpoint at '/cgi-bin/sslvpnclient.
This triggers a false session validation, as the mechanism assumes that the request is related to an active VPN session. This disconnects the victim and gives the attacker access to the session, allowing them to read the user's Virtual Office bookmarks, obtain VPN client, open a VPN tunnel to the internal network, and provide access to private network resources.
See also: Microsoft Patch Tuesday February 2025: Fixes 55 vulnerabilities
SonicWall: Security updates for the vulnerability
The issue affects SonicOS versions 7.1.x (up to 7.1.1-7058), 7.1.2-7019, and 8.0.0-8035. These versions run on many Gen 6 and Gen 7 firewall models, as well as SOHO series devices.
The vulnerability is fixed in SonicOS versions 8.0.0-8037 and later, 7.0.1-5165 and later, 7.1.3-7015 and later, and 6.5.5.1-6n and later . For model-specific information, see the SonicWall bulletin

Given that an exploit is available, administrators should immediately update their systems. In today's digital landscape, where attackers are constantly looking for new ways to exploit system weaknesses, it is vital for organizations to have a strong security strategy.
In addition to promptly applying security patches, it is essential to conduct regular vulnerability assessments and penetration testing. These allow organizations to identify and address potential vulnerabilities before hackers can exploit them. They also help organizations understand their security posture and make informed decisions about necessary updates or enhancements.
See also: Orthanc server vulnerability compromises medical data
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In addition to technical measures, it is important for organizations to invest in employee education and training on security best practices. This can include topics such as using strong passwords, recognizing phishing attempts, and reporting suspicious activity. Educating employees on these topics can significantly reduce the likelihood of successful cyberattacks.
Finally, organizations should have an incident response plan to respond quickly and effectively to potential security incidents. This includes having a designated team and clearly defined procedures for handling such situations.
Source: www.bleepingcomputer.com
