Arctic Wolf Observes Authentication Bypass Exploitation Attempts Targeting SonicWall Firewalls (CVE-2024-53704)
ID: 4ca9a1fa-07e5-5726-aee9-16ae46d4de87
STIX ID: report--4ca9a1fa-07e5-5726-aee9-16ae46d4de87
Feed Name: Arctic Wolf
**Executive summary:** CVE-2024-53704 is a high-severity authentication bypass in SonicOS SSLVPN that can allow unauthenticated actors to bypass MFA, disclose sensitive information, and interrupt VPN sessions; a public PoC was released (10 Feb 2025) and Arctic Wolf observed exploitation attempts, with historical linkage to Akira ransomware affiliates using SonicWall SSL VPN accounts for initial access—organizations should upgrade to the fixed SonicOS versions and restrict SSLVPN exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
