CVE-2024-22396: SonicWall SonicOS

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.

Affected products

  • SonicWall SonicOS: up to and including 7.0.1-5145; up to and including 7.1.1-7047; up to and including 6.5.4.13-105n; up to and including 6.5.4.4-44v-21-2340

Published 2024-03-14. Last modified 2026-06-17.