CVE-2024-40765: SonicWall SonicOS
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a specially crafted IKEv2 payload.
Affected products
- SonicWall SonicOS: up to and including 6.5.4.4-44v-21-2395; up to and including 7.0.1-5151; up to and including 7.1.1-7051
Published 2025-01-09. Last modified 2026-06-17.