logo

CVE-2024-12802: SonicWall SSL-VPN MFA Bypass Persists on Gen6

ID: 47b894d3-6b68-56a4-9259-587253937261

STIX ID: report--47b894d3-6b68-56a4-9259-587253937261

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-22

Author: Ameer Owda

...
...

CVE-2024-12802 is a critical (CVSS 9.1) authentication/MFA bypass in SonicWall SSL‑VPN for AD-integrated environments; Gen6 appliances can remain exploitable after firmware upgrades unless additional manual reconfiguration steps are applied. Researchers reported in-the-wild exploitation (Feb–Mar 2026) where actors brute-forced VPN credentials then bypassed MFA via alternate username formats; defenders should apply SonicWall’s Gen6 remediation steps, hunt for VPN authentication IOCs such as sess="CLI", enforce strong password/lockout controls, and prioritize migrating EOL Gen6 hardware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.