CVE-2024-40766: SonicWall SonicOS Improper Access Control Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-09-09. EPSS: 18.4% chance of exploitation in the next 30 days.

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

Affected products

  • SonicWall SonicOS: before 5.9.2.14-13o (fixed in 5.9.2.14-13o); before 6.5.2.8-2n (fixed in 6.5.2.8-2n); before 6.5.4.15.116n (fixed in 6.5.4.15.116n); up to and including 7.0.1-5035

Published 2024-08-23. Last modified 2026-09-21.