CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-40766

Critical Severity|Sonicwall
84
SVRS
9.8
CVSSv3
0.18177
EPSS
TAGS
In The WildExploit AvaliableCISA KEV
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:UC:HI:HA:H
PUBLICATION DATE2024-08-23
LAST MODIFIED2025-10-21

Deep CVE Analysis in Progress

The system is currently conducting an in-depth analysis of the selected CVE. This includes advanced correlation, vulnerability classification, and cross-referencing with real-time threat intelligence sources. Once the analysis is complete, the page will automatically update with enriched vulnerability data and actionable insights.

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-40766, is an improper access control flaw found in the SonicWall SonicOS management access. It is critical because it can lead to unauthorized access to firewall resources and, in certain conditions, can cause the firewall to crash, resulting in a denial of service. Given that firewalls are critical components of network security, such a vulnerability can severely compromise network integrity, confidentiality, and availability.
2. What are the CVSS score, severity level, and disclosure details?
The CVSS score for this vulnerability is 9.8, which designates it as a Critical severity level. The vulnerability was publicly disclosed and published on 2024-08-23 06:19:07, and the record was last modified on 2025-10-21 22:55:46.
3. Which products, vendors, systems, and versions are affected?
The affected vendor is SonicWall. The vulnerability impacts the following products and versions:
  • SonicWall Firewall Gen 5 devices
  • SonicWall Firewall Gen 6 devices
  • SonicWall Firewall Gen 7 devices running SonicOS 7.0.1-5035 and older versions
4. What is the technical root cause and attack vector?
The technical root cause is an improper access control vulnerability (CWE-284) within the SonicWall SonicOS management access mechanism. This flaw allows attackers to bypass intended security restrictions. The primary attack vector is through the management interface of the affected SonicWall firewall devices.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by leveraging the improper access control flaw in the SonicOS management interface. An attacker can gain unauthorized access to firewall resources. Furthermore, under specific conditions, exploitation can lead to a denial of service by causing the affected firewall to crash. The fact that active exploits have been published indicates that the methods for exploitation are known and potentially publicly available.
6. What mitigation steps and patches are available?
To mitigate this vulnerability, administrators should upgrade their SonicWall Firewall Gen 7 devices to a SonicOS version newer than 7.0.1-5035. For Gen 5 and Gen 6 devices, the latest security patches and firmware updates released by SonicWall should be applied. Additionally, restricting access to the SonicOS management interface to only trusted networks and IP addresses can limit the exposure to potential attackers.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by checking the SonicOS version running on SonicWall Firewall Gen 5, Gen 6, and Gen 7 devices. Specifically, for Gen 7 devices, any installation running SonicOS 7.0.1-5035 or older is considered vulnerable. Administrators should verify their current firmware version against the vendor's advisories for the latest patched versions.
8. What are the indicators of compromise (IOCs)?
Indicators of Compromise (IOCs) for this vulnerability may include:
  • Unauthorized login attempts or successful unauthorized access to the SonicOS management interface.
  • Unexplained reboots or crashes of the SonicWall firewall devices.
  • Unusual configuration changes or unauthorized modifications observed on the firewall.
  • Unexpected network traffic originating from the firewall itself.
  • Entries in firewall logs indicating access from unfamiliar or unauthorized IP addresses to the management interface.
9. Which threat actors are known to exploit this vulnerability?
While the CVE data does not name specific threat actor groups, it explicitly states that "Active exploits have been published to exploit the vulnerability." This indicates that the vulnerability is publicly known and is likely being targeted or actively exploited by various malicious actors, including cybercriminals, state-sponsored groups, or opportunistic attackers.
10. What public intelligence references and advisories exist?
The primary public intelligence reference is CVE-2024-40766 itself. Given that SonicWall is the affected vendor, official security advisories and patches are expected to be published by SonicWall. The existence of published active exploits suggests that details about the exploitation methods may be available in public security research, threat intelligence platforms, or exploit databases.
11. What is the risk assessment and urgency level?
The risk assessment for CVE-2024-40766 is rated as Critical, highlighted by a CVSS score of 9.8. This vulnerability affects critical network infrastructure (firewalls) and can lead to severe consequences such as unauthorized resource access and denial of service. The urgency level is Immediate. Organizations using affected SonicWall devices must prioritize patching and implementing mitigation strategies without delay to protect their networks from active exploitation.
TypeIndicatorDate
IP
66.165.243.392025-07-16Search on IOC Radar
HASH
b365af317ae730a67c936f21432b9c712021-10-03Search on IOC Radar
HASH
a0bdfac3ce1880b32ff9b696458327ce352e3b1d2021-10-03Search on IOC Radar
HASH
bd2c2cf0631d881ed382817afcce2b093f4e412ffb170a719e2762f250abfea42021-10-01Search on IOC Radar
HASH
5537c708edb9a2c21f88e34e8a0f17442022-06-08Search on IOC Radar
HASH
86233a285363c2a6863bf642deab7e20f062b8eb2023-04-15Search on IOC Radar
HASH
26d5748ffe6bd95e3fee6ce184d388a1a681006dc23a0f08d53c083c593c193b2023-03-28Search on IOC Radar
TitleSoftware LinkDate
SonicWall SonicOS Improper Access Control Vulnerabilityhttps://www.cisa.gov/search?g=CVE-2024-407662024-09-09
SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
Incidents de sécurité dans les pare-feux SonicWall (05 août 2025)
2025-08-05
Incidents de sécurité dans les pare-feux SonicWall (05 août 2025) | [Mise à jour du 7 août 2025] Le 6 août 2025, SonicWall a remplacé une partie de son communiqué initial pour indiquer que les incidents de sécurité évoqués étaient vraisemblablement corrélés à la vulnérabilité CVE-2024-40766. Celle-ci a fait l'objet d'un bulletin de sécurité, SNWLID-2024-0015 (cf....
ssi.gouv.frrssforumnews
Vulnérabilité dans SonicWall (10 septembre 2024)
2024-09-10
Vulnérabilité dans SonicWall (10 septembre 2024) | Le 22 août 2024, Sonicwall a publié un correctif concernant la vulnérabilité critique CVE-2024-40766 affectant les pare-feux Sonicwall génération 5, 6 et 7. Cette vulnérabilité, de type contrôle d'accès défaillant, permet à un attaquant de provoquer un déni de service à distance, une atteinte à...
ssi.gouv.frrssforumnews
SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;
Dr. Johannes B. Ullrich2026-06-24
SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln; | Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln; CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration. https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash
sans.edurssforumnews
Erhöhte Bedrohungsaktivität gegen SonicWall Gen 7 Firewalls mit SSLVPN - Sofortmaßnahmen empfohlen
CERT.at2025-08-05
Erhöhte Bedrohungsaktivität gegen SonicWall Gen 7 Firewalls mit SSLVPN - Sofortmaßnahmen empfohlen | 05. August 2025 Update: 07. August 2025 Erg&auml;nzung von technischen Indikatoren f&uuml;r eine forensische Untersuchung m&ouml;glicherweise betroffener Ger&auml;te sowie Informationen zu der angeblich relevanten Schwachstelle. Beschreibung</h2
cve-2024-40766sonicossecuritysoftware publisher
Aktive Ausnutzung einer Sicherheitslücke in SonicWall SonicOS (CVE-2024-40766)
CERT.at2024-09-06
Aktive Ausnutzung einer Sicherheitslücke in SonicWall SonicOS (CVE-2024-40766) | Der Hersteller SonicWall hat am 21.08.2024 ein Advisory zu einer schwerwiegenden Sicherheitsl&uuml;cke in seinem Betriebssystem f&uuml;r Netzwerkger&auml;te, SonicOS, ver&ouml;ffentlicht. Die Ausnutzung besagter Schwachstelle,&nbsp;CVE-2024-40766, k&ouml;nnte es Angreifer:innen erlauben, betroffene Ger&auml;te zum Absturz zu bringen. Zeitgleich mit der Ver&ouml;ffentlichung hat das Unternehmen auch aktualisierte Versionen von SonicOS freigegeben welche das Problem beheben. <
cve-2024-40766globalsonicosr
Ransomware Gangs Now Kill Security Software Before Striking, Report Warns - kobaran.com
2026-07-28
Ransomware Gangs Now Kill Security Software Before Striking, Report Warns - kobaran.com | News Content: Security teams are losing one of their last lines of defense before a ransomware attack even begins. New research shows that disabling endpoint detection and response tools, once a niche skill reserved for the most technically advanced hacking crews, has become routine practice across the ransomware underworld. The finding comes from Halcyon’s Q2 2026 Ransomware Evolution Report, released July 27, which tracked nearly 2,000 publicly claimed ransomware attacks worldwide during the second quarter. According to the report, the technique known as EDR-kill is no longer
cve-2025-5777cve-2024-40766cve-2024-55591europe
SonicWall Zero-Day: CVSS 10.0 Flaw Hits SMA 1000 [2026] - tech-insider.org
2026-07-27
SonicWall Zero-Day: CVSS 10.0 Flaw Hits SMA 1000 [2026] - tech-insider.org | News Content: SonicWall Zero-Days: CVSS 10.0 Bug Exploited 22 Days [2026] July 27, 2026 13 min read SonicWall’s SMA 1000 series appliances carried a live backdoor for at least 22 days before anyone outside the attackers knew it existed. Two vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, let an unidentified threat cluster walk straight past authentication and into root access on internet-facing secure access gateways used by businesses, government agencies, and managed security providers. By the time SonicWall shipped a fix on July 14
cve-2026-15410cve-2024-53704cve-2024-40766cve-2026-15409
avatar
Gagan Suie@gagansuie
30 days ago
How do you pass an OTP prompt you cannot see? Researchers assess the operators are replaying stolen OTP seeds, most likely harvested from earlier exploitation of CVE-2024-40766. Steal the seed, generate the codes forever.
avatar
@pedri77@pedri77
2026-07-02
A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never touched. SonicWall CVE-2024-40766 Proves Patching Is Not Rem... https://t.co/gUf8Ka4I2V
avatar
DFIR Radar@DFIR_Radar
2026-06-27
DFIR Weekly Recap | This week brought zero-days, supply chain hits, and persistent access campaigns across nearly every layer of the enterprise stack. - CVE-2024-40766: SonicWall patch closed the bug but misconfigured devices stayed exposed. - Turla's STOCKSTAY expands the https://t.co/IJOqDdY6Oe
avatar
DFIR Radar@DFIR_Radar
2026-06-27
📌 CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd)
avatar
Meridian Group@MeridianEU
2026-06-26
CVE-2024-40766 in #SonicWall firewalls actively exploited for persistent unauthorized access. Threat actors establish rogue accounts, harvest credentials, and enroll malicious TOTP devices within compromised environments to maintain long-term network access. https://t.co/fbERXRPHMl
avatar
Aviatrix Threat Research Center@aviatrixtrc
2026-06-23
TRC analysis shows ransomware groups exploiting CVE-2024-40766 in SonicWall SSL VPNs to achieve data encryption within 55 minutes of initial compromise. Attackers leverage VPN access for persistent C2 and lateral movement through compromised credentials. Runtime segmentation can
avatar
Shah Sheikh@shah_sheikh
2026-06-23
SonicWall CVE-2024-40766 Proves Patching Is Not Remediation: A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never touched. SonicWall… https://t.co/bLkl6I9bSP https://t.co/Ma8VzuiZ71
avatar
ThreatCluster@threatcluster
2026-06-23
Ransomware groups Akira and Fog have exploited CVE-2024-40766 in SonicWall SonicOS firewalls since September 2024, with nearly 49,000 vulnerable devices exposed publicly as of December 2024, https://t.co/30aYZsWkl1 reported. #Ransomware #Vulnerability https://t.co/UtbedyaMpp
avatar
ThreatCluster@threatcluster
2026-06-23
Akira ransomware operators exploited CVE-2024-40766 via SSL VPNs on SonicWall Gen 7 firewalls, breaching networks and pivoting to domain controllers, Bitdefender and Huntress reported. #Vulnerability #InfoSec https://t.co/ZyPVJmnHp9
avatar
CyberNewsDaily@NewsDaily18579
2026-06-23
🔴 Critical CVE-2024-40766 (CVSS: N/A) [CISA KEV: ACTIVELY EXPLOITED] [EPSS: 15.7%]: A vulnerability was patched but still exploited because misconfigured systems weren't fixed. via SANS ISC https://t.co/jOkFMknPJo
Configuration 1
TypeVendorProduct
OSSonicwallsonicos
ReferenceLink
[email protected]https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
[email protected]https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
CWE IDCWE NameDescription
CWE-284Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.