CVE-2024-40766

Published Aug 23, 2024

Last updated 8 months ago

Exploit knownCVSS critical 9.8
SonicWall SonicOS
Sonicwall
SSL
VPN

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-40766 is an improper access control vulnerability found in SonicWall SonicOS. The vulnerability lies in the SonicOS management access, potentially leading to unauthorized resource access. In specific conditions, this can cause the firewall to crash. The vulnerability affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. It is recommended to restrict firewall management access to trusted sources and ensure that firewall WAN management is not accessible from the public internet. Similarly, limiting SSLVPN access to trusted sources or disabling it from the internet is also advised.

Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Source
PSIRT@sonicwall.com
NVD status
Analyzed
Products
sonicos

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SonicWall SonicOS Improper Access Control Vulnerability
Exploit added on
Sep 9, 2024
Exploit action due
Sep 30, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

PSIRT@sonicwall.com
CWE-284
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never touched. SonicWall CVE-2024-40766 Proves Patching Is Not Rem... https://t.co/gUf8Ka4I2V

    @pedri77

    2 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-40766 patch released, but misconfigurations remain unaddressed, leaving systems exposed. Defenders must verify and harden settings immediately.

    @ThreatPing

    28 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-40766 patch released but misconfigurations remain unaddressed, leaving systems exposed. Defenders must verify secure configurations immediately.

    @ThreatPing

    27 Jun 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. DFIR Weekly Recap | This week brought zero-days, supply chain hits, and persistent access campaigns across nearly every layer of the enterprise stack. - CVE-2024-40766: SonicWall patch closed the bug but misconfigured devices stayed exposed. - Turla's STOCKSTAY expands the http

    @DFIR_Radar

    27 Jun 2026

    235 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    1 Reply

    0 Quotes

  5. CVE-2024-40766 in #SonicWall firewalls actively exploited for persistent unauthorized access. Threat actors establish rogue accounts, harvest credentials, and enroll malicious TOTP devices within compromised environments to maintain long-term network access. https://t.co/fbERXRPH

    @MeridianEU

    26 Jun 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. #SonicWall CVE-2024-40766 Proves #Patching Is Not Remediation https://t.co/hWmOcHmpPO

    @miguelcarvajalm

    23 Jun 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. TRC analysis shows ransomware groups exploiting CVE-2024-40766 in SonicWall SSL VPNs to achieve data encryption within 55 minutes of initial compromise. Attackers leverage VPN access for persistent C2 and lateral movement through compromised credentials. Runtime segmentation can

    @aviatrixtrc

    23 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. SonicWall CVE-2024-40766 Proves Patching Is Not Remediation: A SANS audit of 14 patched SonicWall firewalls shows Akira ransomware still getting in via stale accounts and LDAP misconfigurations the firmware update never touched. SonicWall… https://t.co/bLkl6I9bSP https://t.co

    @shah_sheikh

    23 Jun 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 #GüvenlikBülteni #SiberGüvenlik: SonicWall Güvenlik Duvarlarında Kritik Yetkisiz Erişim Riski (CVE-2024-40766) Bülten Tarihi: 23 Haziran 2026 Referans: CVE-2024-40766 / CISA KEV Etkilenen Cihazlar: SonicWall Gen 5, Gen 6 ve Gen 7 (SonicOS 7.0.1-5035 ve altı) Etki Se

    @rahmid3mir

    23 Jun 2026

    42 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🐛 VULNERABILITIES CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) — SANS ISC https://t.co/ppG4T5Esa9 #Vulnerability #CVE #ZeroDay

    @MalwareObserver

    23 Jun 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Ransomware groups Akira and Fog have exploited CVE-2024-40766 in SonicWall SonicOS firewalls since September 2024, with nearly 49,000 vulnerable devices exposed publicly as of December 2024, https://t.co/30aYZsWkl1 reported. #Ransomware #Vulnerability https://t.co/UtbedyaMpp

    @threatcluster

    23 Jun 2026

    152 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Akira ransomware operators exploited CVE-2024-40766 via SSL VPNs on SonicWall Gen 7 firewalls, breaching networks and pivoting to domain controllers, Bitdefender and Huntress reported. #Vulnerability #InfoSec https://t.co/ZyPVJmnHp9

    @threatcluster

    23 Jun 2026

    90 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  13. 🔴 Critical CVE-2024-40766 (CVSS: N/A) [CISA KEV: ACTIVELY EXPLOITED] [EPSS: 15.7%]: A vulnerability was patched but still exploited because misconfigured systems weren't fixed. via SANS ISC https://t.co/jOkFMknPJo

    @NewsDaily18579

    23 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2024-40766 (CVSS 9.3) in SonicWall SSLVPN has been exploited by Akira and Fog ransomware since Sept 2024. Patching firmware is not remediation: stale accounts, broken LDAP config, and an exposed MFA enrollment portal are keeping patched firewalls wide open. Key findings: -

    @DFIR_Radar

    23 Jun 2026

    329 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  15. 🚨 #CVE-2024-40766: The Patch Was Installed The Breach Path Remained Open + Video -Fact Checker: ✅: 3 ❌: 2 || 3/5 → Score: 60% ⚖️ -Prediction: 📈 3 Positive | 📉 3 Negative https://t.co/q5p7wMOWVR

    @UndercodeNews

    23 Jun 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Vulnérabilité dans SonicWall (10 septembre 2024) — Le 22 août 2024, Sonicwall a publié un correctif concernant la vulnérabilité critique CVE-2024-40766 affectant les pare-feux Sonicwall génération 5, 6 et 7. Cette vulnérabilité, de type contrôle d'accès défaillant,

    @RotateKeys

    6 Mar 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 Marquis Ransomware Breach Hits 74 US Banks, Credit Unions Marquis Software Solutions—a vendor serving 74 US banks and credit unions—got hit by ransomware, exposing financial institution data on 400,000+ customers. What's notable: Akira ransomware exploited CVE-2024-40

    @the_c_protocol

    4 Dec 2025

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Ransomware vulns with highest exploit likelihood ⬆️ (past 30d): - CVE-2024-40766 (SonicOS SSL-VPN..) +64.88% - CVE-2022-27510 (NetScaler ADC..) +21.33% - CVE-2022-27510 (Gateway..) +21.33% - CVE-2021-27877 (Veritas Veritas..) +15.37% - CVE-2021-27876 (Veritas Veritas..) +14.

    @DefusedCyber

    1 Dec 2025

    7197 Impressions

    2 Retweets

    23 Likes

    9 Bookmarks

    2 Replies

    2 Quotes

  19. Alerta sobre ransomware Akira: Operação expande ataques para Nutanix AHV VM encriptando discos via CVE-2024-40766 e explorando vulnerabilidades em firewalls SonicWall, exigindo backups offline e autenticação multifator rápida para proteção eficaz. https://t.co/RJOgQlpsUU

    @caveiratech

    14 Nov 2025

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  20. The ransomware strain Akira has expanded its reach to virtual machines running on Nutanix’s AHV platform. According to a recent advisory, the attack campaign began in June 2025 and exploited a critical vulnerability in SonicWall’s SonicOS (CVE-2024-40766) to gain a foothold.

    @rtehrani

    14 Nov 2025

    82 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  21. The Akira ransomware group has earned over $244M by exploiting VMware ESXi servers and multiple vulnerabilities like CVE-2024-40766 and CVE-2023-28252, using credential theft and brute-force tactics. #AkiraGroup #RansomwareAttack #VMware https://t.co/XdFZRcysSD

    @TweetThreatNews

    14 Nov 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CISA reports Akira ransomware targets Nutanix AHV VMs by encrypting .qcow2 disk files via SonicWall CVE-2024-40766 exploit. Attack uses stolen credentials and minimal platform interaction. #AkiraRansomware #NutanixAHV #USA https://t.co/RRgNhWrF3T

    @TweetThreatNews

    14 Nov 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. CISA identifies Akira ransomware as an imminent threat to U.S. critical infrastructure, leveraging exploits like SonicWall CVE-2024-40766 and Veeam vulnerabilities through VPN and SSH attacks. #AkiraGroup #CriticalInfrastructure #USA https://t.co/BLK3HbCfp4

    @TweetThreatNews

    13 Nov 2025

    55 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Is your SonicWall SSL VPN truly secure? 🔒 The Akira ransomware group is actively exploiting SonicWall SSL VPNs by combining a patched vulnerability (CVE-2024-40766) with a critical security gap: unaddressed legacy accounts. This attack vector is particularly dangerous becaus

    @HunterStrategy

    14 Oct 2025

    100 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 SonicWall SSL VPN 3,894件が露出 — MFAバイパス・OVERSTEP侵入を確認​ 複数のハッキンググループ(Akira、UNC6148)が既知の脆弱性CVE-2024-40766を悪用。​ MFA環境でも侵入事例が発生しており、管理者は即時対応が

    @CriminalIP_JP

    14 Oct 2025

    132 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. اگر از محصول SonicWall SSL VPN استفاده می کنید ، بررسی کنید که آیا آسیب پذیری با کد شناسایی CVE-2024-40766 پچ شده است یا خیر . به تازگی باج افزار Akira از این آسیب پذیری برای

    @AmirHossein_sec

    12 Oct 2025

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨CVE-2024-40766: Critical Improper Access Control Vulnerability Affecting SonicWall Devices CVSS: 9.3 FOFA: https://t.co/LxTe42aUQN Results: 473,950 FOFA Query: app="SONICWALL-SSL-VPN" Advisory: https://t.co/4Gpw41Btwg https://t.co/2vHVqxgPlV

    @DarkWebInformer

    10 Oct 2025

    6286 Impressions

    7 Retweets

    29 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  28. SonicWall ファイアウォールを標的とする攻撃:Akira ランサムウェアによるログイン試行を分析 https://t.co/Ctt5l1tuRD SonicWall SSL VPN の脆弱性 CVE-2024-40766 を起点に、認証情報が悪用され、Akira

    @iototsecnews

    8 Oct 2025

    188 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Akira Reloaded https://t.co/n9P8eEJttx Akira ransomware attacks have surged since July 2025, exploiting a vulnerability in SonicWall VPNs (CVE-2024-40766) to gain rapid access to organizational networks. These attacks are characterized by their speed, with some intrusions comp

    @f1tym1

    7 Oct 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    5 Oct 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. Akira ransomware group exploits CVE-2024-40766 and stolen SonicWall VPN credentials to breach and encrypt networks in under four hours, bypassing MFA and using advanced lateral movement techniques. #SonicWallVPN #AkiraRansomware #USA https://t.co/YnakNBRApy

    @TweetThreatNews

    30 Sept 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Cyber threat update hot off the press 🚨 – critical malware, sophisticated frauds, major vulnerabilities, and espionage cases unveiled in the last hour: 🛡️ SonicWall firewalls (Gen 5-7) under active attack exploiting CVE-2024-40766 SSL VPN flaw to deploy Akira ransomwar

    @np_cyber_news

    30 Sept 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. [SonicWall CVE-2024-40766] Arctic Wolf révèle que la récente campagne ransomware Akira a compromis des comptes utilisateurs via le contournement du MFA. https://t.co/r6U3lXsZdo

    @cert_ist

    29 Sept 2025

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Since mid-2025, attackers are exploiting a severe vulnerability in SonicWall SSL VPNs (CVE-2024-40766). It's a wake-up call: patching is non-negotiable! #GRC #VulnerabilityManagement

    @Cyb3r_5wift

    29 Sept 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Akira ransomware exploits CVE-2024-40766 to breach SonicWall SSL VPN devices, bypassing MFA using stolen OTP seeds or other means. Attacks include rapid scanning, credential theft, and lateral movement. #AkiraRansomware #VPNBreach #USA https://t.co/IYXmxaL7WX

    @TweetThreatNews

    28 Sept 2025

    124 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  36. Akiraランサムウェア集団が多要素認証で保護されたSonicWallのVPNアカウントを侵害している。Arctic Wolf社報告。SonicWall公式はCVE-2024-40766関連だとしている。金銭目的のUNC6148集団が窃取済みのOTPシードを用いてOVERST

    @__kokumoto

    28 Sept 2025

    1292 Impressions

    3 Retweets

    6 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  37. Zero-day vulnerabilities lurk in popular software, unseen until exploited. Attacks like Stuxnet, Log4Shell, and CVE-2024-40766 reveal their devastating impact. Defending against them demands a strong defense-in-depth strategy to detect, contain, and recover. https://t.co/65KxYPjK

    @The4n6Analyst

    24 Sept 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🚨 Akira ransomware explota fallas en SonicWall SSL VPN y errores de configuración para acceder a redes corporativas. 🔓 CVE-2024-40766 + LDAP mal configurado = acceso no autorizado. 🔗https://t.co/VIhrxxRAwA #Ransomware #Akira #SonicWall #CyberSecurity #VPN #ThreatIntel #

    @trustlock_sec

    19 Sept 2025

    17 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. The #Akira ransomware group is back in action, exploiting a critical vulnerability (CVE-2024-40766) in SonicWall SSL VPN devices that was previously patched in August 2023. Affected #SonicWall versions include Gen 5, Gen 6, and Gen 7. https://t.co/djFwL9lzmp

    @devcentral

    19 Sept 2025

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 🚨 BREAKING SONICWALL : Violation MySonicWall expose configurations de 5% des pare-feu mondiaux ! Attaques brute-force API + CVE-2024-40766 = tempête parfaite cybercriminelle. https://t.co/tuprLhtm4C #SonicWall #MySonicWall #DataBreach #CyberSecurity #FirewallSecurity http

    @ctrlaltnod

    18 Sept 2025

    2 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Researchers and authorities are warning that Akira ransomware attacks involving exploits of a year-old vulnerability affecting SonicWall firewalls are on the rise. A burst of about 40 attacks linked to CVE-2024-40766 hit SonicWall firewalls between mid-July and early August. ht

    @CyberScoopNews

    16 Sept 2025

    445 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  42. Researchers and authorities are warning that Akira ransomware attacks involving exploits of a year-old vulnerability affecting SonicWall firewalls are on the rise. A burst of about 40 attacks linked to CVE-2024-40766 hit SonicWall firewalls between mid-July and early August. ht

    @CyberScoopNews

    15 Sept 2025

    353 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. This is your Monday reminder to immediately apply patches if you are using SonicWall firewalls. The Akira ransomware group is actively attacking SonicWall firewalls by exploiting a known, year-old vulnerability (CVE-2024-40766: https://t.co/FqaWEywjKU

    @CybelAngel

    15 Sept 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Researchers and authorities are warning that Akira ransomware attacks involving exploits of a year-old vulnerability affecting SonicWall firewalls are on the rise. A burst of about 40 attacks linked to CVE-2024-40766 hit SonicWall firewalls between mid-July and early August. ht

    @CyberScoopNews

    14 Sept 2025

    491 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Top 5 Trending CVEs: 1 - CVE-2024-40766 2 - CVE-2025-54135 3 - CVE-2018-20587 4 - CVE-2022-46689 5 - CVE-2025-32756 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    14 Sept 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Critical Threat Alert: The SonicWall SSL VPN vulnerability (CVE-2024-40766) is being actively exploited by Akira Ransomware. Our guide provides the full threat intel and defense strategies. Read the full report: https://t.co/ks145AMJKc https://t.co/btW5RtlZco

    @cyberbivash

    13 Sept 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. HybridPetya ransomware exploits CVE-2024-7344 to bypass UEFI Secure Boot. Akira targets SonicWall SSLVPN with CVE-2024-40766. Panama Ministry breached amid widespread patches for DELMIA, Cisco IOS XR, Samsung, Adobe. #Panama #UEFESecurity #SonicWall https://t.co/LEB3rIOUoE

    @TweetThreatNews

    13 Sept 2025

    445 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  48. Akira ransomware affiliates continue exploiting CVE-2024-40766 in SonicWall firewalls, targeting organizations globally through misconfigurations and outdated software amid firewall migrations. #SonicWall #Ransomware #USA https://t.co/1mj0j79foI

    @TweetThreatNews

    12 Sept 2025

    174 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 📝 𝐒𝐨𝐧𝐢𝐜𝐖𝐚𝐥𝐥 𝐟𝐢𝐫𝐞𝐰𝐚𝐥𝐥𝐬 𝐭𝐚𝐫𝐠𝐞𝐭𝐞𝐝 𝐛𝐲 𝐟𝐫𝐞𝐬𝐡 𝐀𝐤𝐢𝐫𝐚 𝐫𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞 𝐬𝐮𝐫𝐠𝐞 • Akira ransomware attacks exploiting SonicWall fir

    @PurpleOps_io

    12 Sept 2025

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Akira ransomware exploits three SonicWall flaws—including CVE-2024-40766 and SSLVPN misconfigs—to breach networks fast. Patch, enable MFA, and restrict access now. 🔐⚠️ #AkiraRansomware #Vulnerability https://t.co/pQZMaIqLtf

    @manuelbissey

    12 Sept 2025

    101 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

  1. Issue summary: The implementations of AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) mishandle the authentication of AAD (Additional Authenticated Data) with an empty ciphertext allowing a forgery of such messages. Impact summary: An attacker can forge empty messages with arbitrary AAD to the victim's application using these ciphers. AES-SIV (RFC 5297) and AES-GCM-SIV (RFC 8452) are nonce-misuse-resistant AEAD modes: they accept a key, nonce, optional AAD (bytes that are authenticated but not encrypted), and plaintext, and produces ciphertext plus a 16-byte tag. On decrypt, `EVP_DecryptFinal_ex()` is documented to return success only if the tag is verified succesfully. In OpenSSL's provider implementation of these ciphers, the expected tag is computed only when decryption function is invoked with non-empty data. If the caller supplies AAD and then calls `EVP_DecryptFinal_ex()` without invocation of the ciphertext update, which can happen when the received ciphertext length is zero, the tag is never recalculated and still holds its all-zeros value. When AES-GCM-SIV is used, an attacker who sends arbitrary AAD, empty ciphertext, and all-zeros tag passes authentication under any key they do not know, single-shot. When AES-SIV is used, for mounting the attack it's necessary for the application to reuse the decryption context without resetting the key. AES-SIV is implemented since OpenSSL 3.0. AES-GCM-SIV is implemented since OpenSSL 3.2. No protocols implemented in OpenSSL itself (TLS/CMS/PKCS7/HPKE/QUIC) support either AES-GCM-SIV or AES-SIV. To mount an attack, the applications must implement their own protocol and use the EVP interface. Also they must skip the ciphertext update when a message with an empty ciphertext arrives. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as these algorithms are not FIPS approved and the affected code is outside the OpenSSL FIPS module boundary.CVE-2026-45446
  2. Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the application-supplied initialisation vector (IV) is silently discarded. Impact summary: Every message encrypted under the same key uses the same effective nonce regardless of the IV supplied by the caller, resulting in (key, nonce) reuse and loss of confidentiality. If the same code path is used to compute the authentication tag, the tag depends only on the (key, IV) pair and not on the plaintext or ciphertext, allowing universal forgery of arbitrary ciphertext from a single captured message. OpenSSL provides two ways to drive a cipher: the documented streaming interface (EVP_CipherUpdate / EVP_CipherFinal_ex) and a lower-level one-shot, EVP_Cipher(), whose documentation explicitly recommends against use by applications in favour of EVP_CipherUpdate() and EVP_CipherFinal_ex(). The OCB provider's streaming handler flushes the application-supplied IV into the OCB context before processing data; the one-shot handler did not. Every call to EVP_Cipher() on an AES-OCB context therefore ran with the all-zero key-derived offset state left by cipher initialisation, regardless of the caller's IV. If EVP_EncryptFinal_ex() is subsequently used to obtain the authentication tag, the deferred IV setup runs at that point and clears the running checksum that should have been accumulated over the plaintext. The resulting tag is a function of (key, IV) only and verifies against any ciphertext produced under the same (key, IV) pair. The OpenSSL SSL/TLS implementation is not affected: AES-OCB is not a TLS cipher suite, and libssl does not call EVP_Cipher() in any case. Applications that drive AES-OCB through the documented streaming AEAD API (EVP_CipherUpdate / EVP_CipherFinal_ex) are not affected. Only applications that combine the AES-OCB cipher with the EVP_Cipher() one-shot API are vulnerable. The FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by this issue, as AES-OCB is outside the OpenSSL FIPS module boundary.CVE-2026-45445