CVE-2024-53704: SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-02-18. EPSS: 95.1% chance of exploitation in the next 30 days.

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Affected products

  • SonicWall SonicOS: from 7.1.1-7040, up to and including 7.1.1-7058; version 7.1.2-7019 only; version 8.0.0-8035 only

Published 2025-01-09. Last modified 2026-08-04.