Critical SonicWall Firewall Vulnerability: Patch Now to Secure Your Network

SonicWall issues a critical patch for CVE-2024-40766, a firewall vulnerability that risks unauthorized access. Update your devices now

By
Emily Roberts
August 27, 2024
2
min read
Critical SonicWall Firewall Vulnerability: Patch Now to Secure Your Network

Critical SonicWall Firewall Vulnerability: Patch Now to Secure Your Network

SonicWall has recently released a crucial security patch to address a high-severity vulnerability in its firewall devices. This flaw, identified as CVE-2024-40766 with a CVSS score of 9.3, poses a significant risk by potentially allowing unauthorized access to affected devices.

The vulnerability stems from improper access control within the SonicOS management interface, which could not only enable malicious actors to gain unauthorized access but also, in certain scenarios, lead to a system crash.

This issue affects several generations of SonicWall devices, including:

  • SOHO (Gen 5 Firewalls): Version 5.9.2.14-13o
  • Gen 6 Firewalls: Version 6.5.2.8-2n for SM9800, NSsp 12400, and NSsp 12800 models, and Version 6.5.4.15.116n for other Gen 6 models
  • Gen 7 Firewalls: Any device running SonicOS 7.0.1-5035 or earlier versions

SonicWall has confirmed that this vulnerability does not exist in SonicOS firmware versions higher than 7.0.1-5035. However, they strongly recommend all users to update to the latest firmware version as a precautionary measure.

While there’s no indication that this flaw has been exploited in the wild, it’s imperative to act swiftly. If you can’t immediately apply the patch, ensure that firewall management access is restricted to trusted sources, or consider disabling WAN management access from the internet entirely.

This incident brings to mind last year’s discovery by Mandiant of a China-based threat actor, UNC4540, targeting unpatched SonicWall Secure Mobile Access (SMA) 100 appliances to install persistent backdoors. As attackers increasingly shift their focus to edge infrastructure, vulnerabilities like this one become prime targets.

Take action now to protect your network. Apply the patch, restrict access, and stay vigilant against potential threats. SonicWall’s prompt response underscores the critical need for regular updates and robust security measures to keep your systems secure.

Stay Ahead of Cyber Threats with Hedgehog Security

At Hedgehog Security, we prioritize your network’s safety. Our expert team of Cyber Defenders at SOC365 stays on top of the latest security developments, ensuring your defenses are always up-to-date. Need help securing your SonicWall devices? Reach out to us—we’re here to keep the pricks on the outside, so you can focus on your business.

Share this post