CVE-2024-12802: SonicWall SSL-VPN MFA Bypass Persists on Gen6
ID: 47b894d3-6b68-56a4-9259-587253937261
STIX ID: report--47b894d3-6b68-56a4-9259-587253937261
Feed Name: SOCRadar Blog
CVE-2024-12802 is a critical (CVSS 9.1) authentication/MFA bypass in SonicWall SSL‑VPN for AD-integrated environments; Gen6 appliances can remain exploitable after firmware upgrades unless additional manual reconfiguration steps are applied. Researchers reported in-the-wild exploitation (Feb–Mar 2026) where actors brute-forced VPN credentials then bypassed MFA via alternate username formats; defenders should apply SonicWall’s Gen6 remediation steps, hunt for VPN authentication IOCs such as sess="CLI", enforce strong password/lockout controls, and prioritize migrating EOL Gen6 hardware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
