SonicWall has recently released a crucial security patch to address a high-severity vulnerability in its firewall devices. This flaw, identified as CVE-2024-40766 with a CVSS score of 9.3, poses a significant risk by potentially allowing unauthorized access to affected devices.
The vulnerability stems from improper access control within the SonicOS management interface, which could not only enable malicious actors to gain unauthorized access but also, in certain scenarios, lead to a system crash.
This issue affects several generations of SonicWall devices, including:
SonicWall has confirmed that this vulnerability does not exist in SonicOS firmware versions higher than 7.0.1-5035. However, they strongly recommend all users to update to the latest firmware version as a precautionary measure.
While there’s no indication that this flaw has been exploited in the wild, it’s imperative to act swiftly. If you can’t immediately apply the patch, ensure that firewall management access is restricted to trusted sources, or consider disabling WAN management access from the internet entirely.
This incident brings to mind last year’s discovery by Mandiant of a China-based threat actor, UNC4540, targeting unpatched SonicWall Secure Mobile Access (SMA) 100 appliances to install persistent backdoors. As attackers increasingly shift their focus to edge infrastructure, vulnerabilities like this one become prime targets.
Take action now to protect your network. Apply the patch, restrict access, and stay vigilant against potential threats. SonicWall’s prompt response underscores the critical need for regular updates and robust security measures to keep your systems secure.
Stay Ahead of Cyber Threats with Hedgehog Security
At Hedgehog Security, we prioritize your network’s safety. Our expert team of Cyber Defenders at SOC365 stays on top of the latest security developments, ensuring your defenses are always up-to-date. Need help securing your SonicWall devices? Reach out to us—we’re here to keep the pricks on the outside, so you can focus on your business.