Many IT teams believe they “just updated the firmware” and their VPN is secure. But new reports show that on SonicWall Gen6 SSL-VPN appliances, attackers can bypass MFA when CVE-2024-12802 is not addressed with the necessary manual steps. The result? Attacks start with brute-force/credential stuffing and end up with “legit”-looking access in the logs, paving the way for ransomware tooling.
See also: Security Alarm for SonicWall SMA Devices

What happened in the attacks studied?
According to the analysis presented, responders encountered multiple intrusions between February and March, where the attacker:
– brute-forced VPN credentials,
– logged into a SonicWall SSL-VPN without being "cut off" by MFA,
– stayed inside for 30–60 minutes for recon and credential reuse testing,
– attempted to deploy a Cobalt Strike beacon and vulnerable driver (BYOVD) to potentially disable EDR.
In at least one incident, access from a VPN to a domain-joined file server was achieved within about half an hour, while the attacker opened an RDP session using a shared local admin password. CVE-2024-12802 is related to “missing MFA enforcement” when using the UPN login format, allowing an attacker with valid credentials to authenticate without triggering the MFA requirement. The crucial point: SonicWall has warned that in Gen6, a firmware update alone is not enough, a manual change to the LDAP configuration is also required — otherwise, bypass is still possible.
See also: Hackers Target SonicWall Firewalls from 4,000+ IP Addresses

- For Gen7/Gen8, updating to newer firmware is reported to be sufficient to eliminate the risk.
- For Gen6, update + manual remediation (LDAP reconfiguration) is required.
- Additionally, it is noted that Gen6 SSL-VPN appliances have reached end-of-life on April 16th (and therefore, overall, the strategy should be migration to supported devices).
Based on the instructions provided, admins should complete the following:
1) Delete the existing LDAP configuration that uses userPrincipalName in the “Qualified login name”.
2) Remove locally cached/listed LDAP users.
3) Remove the SSL VPN “User Domain” (reverts to LocalDomain).
4) Reboot the firewall.
5) Recreate the LDAP configuration without userPrincipalName in the “Qualified login name”.
6) Take a new backup (so as not to restore to a vulnerable config).
See also: Marquis sues SonicWall for breach that led to ransomware

Many SMEs, accounting firms, engineering firms, schools/tutoring centers and organizations use SSL-VPN appliances for remote access. If you have SonicWall Gen6, the case shows that “update” is not enough: you need to check the config and hunt for suspicious entries. For companies that have external partners, shared local admin passwords and RDP to servers, the risk escalates — because an attacker can move laterally in less than an hour.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
