SonicWall SSLVPN access control flaw is now exploited in attacks
ID: 53517b5b-562d-53b9-975b-6f5ff6da4c1c
STIX ID: report--53517b5b-562d-53b9-975b-6f5ff6da4c1c
Feed Name: Bleeping Computer
Threat Score
SonicWall has issued an urgent advisory for CVE-2024-40766, a critical (CVSS 9.3) access-control flaw in SonicOS affecting Gen5/6/7 devices including SSLVPN; administrators are urged to apply vendor patches and mitigations (restrict management access, disable or limit SSLVPN, enforce MFA and password resets). The vendor reports potential exploitation in the wild and security firms have observed Akira ransomware campaigns targeting this vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
