Zoom Vulnerability Alert


Top Advisory

SonicWall Products Denial of Service Vulnerability

Ref: CERT / 2024/09/81

Date: 10/09/2024

Severity Level: HIGH

Components Affected

Overview

A vulnerability has been identified in SonicWall Products. A remote user can exploit this vulnerability to trigger security restriction bypass and denial of service condition on the targeted system.

Note: CVE-2024-40766 is potentially being exploited in the wild. An improper access control vulnerability has been identified in the SonicWall SonicOS management access and SSLVPN, potentially leading to unauthorized resource access and, in specific conditions, causing the firewall to crash.

The risk level is rated as Extremely High Risk.

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and, in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

Impact

Solution/Workarounds

Before installation of the software, please visit the vendor website for more details.

Apply fixes issued by the vendor: SonicWall Security Advisory

Reference

Disclaimer

The information provided herein is on an "as-is" basis, without warranty of any kind.

Footer Advisory