CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
EPSS Prediction
Documented as more likely to be exploited than 88.2% of known CVEs.
Sep 09, 2024
Sep 30, 2024
Threat Analysis
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
External Intelligence
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/kA1VN0000000RDG0A2
https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/kA1VN0000000RDG0A2
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2024-40766