CVE-2024-40766
Executive Summary
An improper access control flaw in SonicWall SonicOS management allows attackers to gain unauthorized access to firewall resources and, under certain conditions, crash the device. The issue impacts Gen 5, Gen 6, and Gen 7 SonicWall firewalls running SonicOS 7.0.1‑5035 or earlier. CISA has listed the CVE as a KEV, indicating active exploitation in the wild.
Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2024-08-23T07:15:03.643 - Last Modified: 2026-09-21T21:17:02.403
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2024-09-09)
Original Description: An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
"A man is not where he lives but where he loves."
— Unknown