CVE-2024-40766

CVE Published 2024-08-23
Related CWE(s) CWE-284: Improper Access Control
Related Vendor(s) sonicwall
Related Product(s) sonicos
Exploitation Reported (CISA KEV) 2024-09-09
CVSS 3 Base Score 9.3 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References