CVE-2024-40766

Published Aug 23, 2024

Last updated a year ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-40766 is an improper access control vulnerability found in SonicWall SonicOS. The vulnerability lies in the SonicOS management access, potentially leading to unauthorized resource access. In specific conditions, this can cause the firewall to crash. The vulnerability affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. It is recommended to restrict firewall management access to trusted sources and ensure that firewall WAN management is not accessible from the public internet. Similarly, limiting SSLVPN access to trusted sources or disabling it from the internet is also advised.

Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Source
PSIRT@sonicwall.com
NVD status
Analyzed
Products
sonicos

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SonicWall SonicOS Improper Access Control Vulnerability
Exploit added on
Sep 9, 2024
Exploit action due
Sep 30, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
PSIRT@sonicwall.com
CWE-284

Social media

Hype score
Not currently trending
  1. Zero-day vulnerabilities lurk in popular software, unseen until exploited. Attacks like Stuxnet, Log4Shell, and CVE-2024-40766 reveal their devastating impact. Defending against them demands a strong defense-in-depth strategy to detect, contain, and recover. https://t.co/65KxYPjK

    @The4n6Analyst

    24 Sept 2025

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Akira ransomware explota fallas en SonicWall SSL VPN y errores de configuración para acceder a redes corporativas. 🔓 CVE-2024-40766 + LDAP mal configurado = acceso no autorizado. 🔗https://t.co/VIhrxxRAwA #Ransomware #Akira #SonicWall #CyberSecurity #VPN #ThreatIntel #

    @trustlock_sec

    19 Sept 2025

    17 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. The #Akira ransomware group is back in action, exploiting a critical vulnerability (CVE-2024-40766) in SonicWall SSL VPN devices that was previously patched in August 2023. Affected #SonicWall versions include Gen 5, Gen 6, and Gen 7. https://t.co/djFwL9lzmp

    @devcentral

    19 Sept 2025

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 BREAKING SONICWALL : Violation MySonicWall expose configurations de 5% des pare-feu mondiaux ! Attaques brute-force API + CVE-2024-40766 = tempête parfaite cybercriminelle. https://t.co/tuprLhtm4C #SonicWall #MySonicWall #DataBreach #CyberSecurity #FirewallSecurity http

    @ctrlaltnod

    18 Sept 2025

    2 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Researchers and authorities are warning that Akira ransomware attacks involving exploits of a year-old vulnerability affecting SonicWall firewalls are on the rise. A burst of about 40 attacks linked to CVE-2024-40766 hit SonicWall firewalls between mid-July and early August. ht

    @CyberScoopNews

    16 Sept 2025

    445 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  6. Researchers and authorities are warning that Akira ransomware attacks involving exploits of a year-old vulnerability affecting SonicWall firewalls are on the rise. A burst of about 40 attacks linked to CVE-2024-40766 hit SonicWall firewalls between mid-July and early August. ht

    @CyberScoopNews

    15 Sept 2025

    353 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. This is your Monday reminder to immediately apply patches if you are using SonicWall firewalls. The Akira ransomware group is actively attacking SonicWall firewalls by exploiting a known, year-old vulnerability (CVE-2024-40766: https://t.co/FqaWEywjKU

    @CybelAngel

    15 Sept 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Researchers and authorities are warning that Akira ransomware attacks involving exploits of a year-old vulnerability affecting SonicWall firewalls are on the rise. A burst of about 40 attacks linked to CVE-2024-40766 hit SonicWall firewalls between mid-July and early August. ht

    @CyberScoopNews

    14 Sept 2025

    491 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Top 5 Trending CVEs: 1 - CVE-2024-40766 2 - CVE-2025-54135 3 - CVE-2018-20587 4 - CVE-2022-46689 5 - CVE-2025-32756 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    14 Sept 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Critical Threat Alert: The SonicWall SSL VPN vulnerability (CVE-2024-40766) is being actively exploited by Akira Ransomware. Our guide provides the full threat intel and defense strategies. Read the full report: https://t.co/ks145AMJKc https://t.co/btW5RtlZco

    @Iambivash007

    13 Sept 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. HybridPetya ransomware exploits CVE-2024-7344 to bypass UEFI Secure Boot. Akira targets SonicWall SSLVPN with CVE-2024-40766. Panama Ministry breached amid widespread patches for DELMIA, Cisco IOS XR, Samsung, Adobe. #Panama #UEFESecurity #SonicWall https://t.co/LEB3rIOUoE

    @TweetThreatNews

    13 Sept 2025

    445 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  12. Akira ransomware affiliates continue exploiting CVE-2024-40766 in SonicWall firewalls, targeting organizations globally through misconfigurations and outdated software amid firewall migrations. #SonicWall #Ransomware #USA https://t.co/1mj0j79foI

    @TweetThreatNews

    12 Sept 2025

    174 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 📝 𝐒𝐨𝐧𝐢𝐜𝐖𝐚𝐥𝐥 𝐟𝐢𝐫𝐞𝐰𝐚𝐥𝐥𝐬 𝐭𝐚𝐫𝐠𝐞𝐭𝐞𝐝 𝐛𝐲 𝐟𝐫𝐞𝐬𝐡 𝐀𝐤𝐢𝐫𝐚 𝐫𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞 𝐬𝐮𝐫𝐠𝐞 • Akira ransomware attacks exploiting SonicWall fir

    @PurpleOps_io

    12 Sept 2025

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Akira ransomware exploits three SonicWall flaws—including CVE-2024-40766 and SSLVPN misconfigs—to breach networks fast. Patch, enable MFA, and restrict access now. 🔐⚠️ #AkiraRansomware #Vulnerability https://t.co/pQZMaIqLtf

    @manuelbissey

    12 Sept 2025

    101 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 一世を風靡したFirewallのSonicwallのVPN脆弱性がRansomwareの餌食になる CVE-2024-40766脆弱性問題が未解決で起こる乗っ取り。かって強固で知られたファイヤーウォールの名門ですが、最近は元気ないのでしょうか? http

    @innovative_ec

    12 Sept 2025

    10 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Researchers warn that the Akira ransomware group exploits a year-old SonicWall flaw (CVE-2024-40766) using multiple vectors for access, urging users to secure accounts and apply patches to prevent unauthorized access. #CyberSecurity #Ransomware https://t.co/Hu71kxBimU

    @Cyber_O51NT

    12 Sept 2025

    556 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  17. CVE-2024-40766 Detail https://t.co/DOmw14fxGn

    @chasster123

    11 Sept 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers. Attacks exploit a year-old security flaw (CVE-2024-40766, CVSS score: 9.3) where local user passwords were carried over during the migration and not reset. https://t.co/xEOW0mJnDx https:/

    @riskigy

    11 Sept 2025

    74 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Since late July 2025, Akira hackers have targeted SonicWall firewalls, exploiting a year-old vulnerability (CVE-2024-40766) alongside misconfigurations. Don't let complacency be your downfall! 🔒 #ThreatHunting

    @Cyb3r_5wift

    11 Sept 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Akira ransomware is exploiting a critical, year-old SonicWall SSLVPN bug (CVE-2024-40766) for unauthorized access. Patch now! 🚨 https://t.co/nFPi2p3dHD #AkiraRansomware #SonicWall #CVE202440766

    @0xT3chn0m4nc3r

    11 Sept 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Akira ransomware exploiting critical SonicWall SSLVPN bug again The Akira ransomware gang is actively exploiting CVE-2024-40766, a year-old critical-severity access co… https://t.co/yUvGA9oWMq https://t.co/cPgS1fruUf

    @DConsultinguk

    11 Sept 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Urgent Warning! The ACSC is warning that a critical SonicWall vulnerability (CVE-2024-40766) is being actively exploited. Our exclusive report has the full analysis. #SonicWall #Cybersecurity #CVE https://t.co/5cukKLOw1q https://t.co/wBHdzn2vxs

    @Iambivash007

    11 Sept 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Vulnerability Alert: Akira ransomware is exploiting SonicWall SSL VPNs via CVE-2024-40766 (CVSS 9.3), LDAP misconfigs, and exposed portals. Initial access = RCE, data theft, ransomware. Mitigate: • Rotate local creds • Enforce MFA • Restrict access https://t.co/1VYrFOfO6n

    @CloneSystemsInc

    11 Sept 2025

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Срочное предупреждение! В Австралии выявлена уязвимость CVE-2024-40766, затрагивающая устройства SonicWall SSL VPN. Хакеры используют этот недостаток для несанкцион

    @cybereye_ru

    11 Sept 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🔒 Did you know CVE-2024-40766 has a staggering CVSS score of 9.8? 🚨 Akira ransomware is targeting SonicWall devices, exploiting potential zero-day vulnerabilities! #Cybersecurity #Ransomware https://t.co/XsUW0OxMvd

    @Cyb3r_5wift

    11 Sept 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Australia’s Cyber Security Centre alerts on active exploitation of CVE-2024-40766 in SonicWall SSL VPN devices, enabling Akira ransomware to bypass controls and crash firewalls. Firmware updates and credential resets critical. #SonicWallVPN #RansomwareAt… https://t.co/G5juQiB

    @TweetThreatNews

    11 Sept 2025

    144 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  27. 🚨 Akira ransomware is back — hammering SonicWall VPNs through a year-old flaw (CVE-2024-40766, CVSS 9.3). One misstep in SonicWall’s LDAP “Default User Group” can hand attackers VPN + admin access the moment they steal a password. Akira has already hit 967 victims an

    @TheHackersNews

    11 Sept 2025

    77187 Impressions

    56 Retweets

    150 Likes

    26 Bookmarks

    0 Replies

    2 Quotes

  28. Ongoing active exploitation of SonicWall SSL VPNs in Australia (CVE-2024-40766) https://t.co/XqExgv8Fd6

    @Dinosn

    10 Sept 2025

    1722 Impressions

    2 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Undisclosed SonicWall Zero Day Leading to Akira Ransomware https://t.co/5C3rieuDIu SonicWall has linked recent SSLVPN security incidents to CVE-2024-40766, affecting Gen 7 and newer firewalls, with less than 40 identified incidents primarily during Gen 6 to Gen 7 migrations wh

    @f1tym1

    15 Aug 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. https://t.co/PTt8waIIpy SonicWall confirms recent SSL-VPN incidents on Gen 7+ firewalls aren’t caused by a zero-day, but tied to the known CVE-2024-40766. Most cases involved Gen 6 → Gen 7 password reuse without resets. #SonicWall #VulnerabilityManagement

    @AnomalousBytes

    11 Aug 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    10 Aug 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  32. #VeilleCyber : 📱 #Bouygues : 6,4M clients exposés (IBAN, coordonnées) 🖥️ Millions de PC #Dell vulnérables aux backdoors #ReVault ✈️ #AirFranceKLM : fuite CRM par #ShinyHunters 🔐 #SonicWall : attaques sur CVE-2024-40766 Détails et conseils 👇 https://t.co/PNV

    @VeilleCyber_fr

    10 Aug 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. SonicWall has dismissed zero-day vulnerability fears after investigating recent ransomware attacks, confirming they stem from the known flaw CVE-2024-40766, urging users to update firmware and reset passwords for improved security. #Cybersecurity #Ransom… https://t.co/kCZQAMfKd

    @Cyber_O51NT

    9 Aug 2025

    264 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. SonicWall says that recent Akira ransomware attacks exploiting Gen 7 firewalls with SSLVPN enabled are exploiting an older vulnerability rather than a zero-day flaw. The company says that the attackers are targeting CVE-2024-40766, fixed in August 2024. https://t.co/OiXMymOkGF ht

    @riskigy

    8 Aug 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. #sonicwall says recent Gen 7 firewall hacks were not a zero-day but exploited CVE-2024-40766, tied to reused legacy passwords during migrations. Fewer than 40 confirmed cases, with Akira ransomware deployed. Users urged to update and reset credentials. https://t.co/eVP2kVNdhC

    @Prevent_Cyber

    8 Aug 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. SonicWall confirms no zero-day vulnerabilities are being exploited despite reports of targeted ransomware attacks linked to CVE-2024-40766. Weak password management during device migration facilitated the breaches. #CyberDefense #Ransomware #Japan https://t.co/rT85TfKOaX

    @TweetThreatNews

    7 Aug 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. #SonicWall updated its advisory on the recent campaign against its firewalls, claiming the incidents are likely tied to the exploitation of CVE-2024-40766 and not a new bug They are investigating about 40 incidents https://t.co/R9A2sCHPhj

    @jgreigj

    7 Aug 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🚨 SonicWall Vulnerability Exploited in August Akira Campaign Recent Akira ransomware intrusions have been linked to CVE-2024-40766, a previously disclosed vulnerability affecting SonicWall firewall appliances. Initial reporting suggested the possibility of a zero-day https://

    @mox_five

    7 Aug 2025

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. SonicWall confirmed that recent attacks on its Gen 7 firewalls with SSL VPN are linked to CVE-2024-40766, a patched vulnerability (CVSS score: 9.3) related to improper access control. https://t.co/MgAdr2D927

    @securityRSS

    7 Aug 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 📌 سونيك وول أكدت أن الهجمات الأخيرة على جدران الحماية من الجيل السابع وما فوق المتعلقة بـ SSL VPN ناتجة عن ثغرة قديمة تم تصحيحها وإعادة استخدام كلمات المرور

    @Cybercachear

    7 Aug 2025

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 🚨 Attackers are hitting SonicWall firewalls again—but it’s not a new zero-day. Turns out, they’re exploiting a known bug (CVE-2024-40766) and weak password hygiene. Migrating from Gen 6 to Gen 7 without resets? That’s leaving doors wide open. Fu... https://t.co/zf

    @IT_news_for_all

    7 Aug 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 🚨 Attackers are hitting SonicWall firewalls again—but it’s not a new zero-day. Turns out, they’re exploiting a known bug (CVE-2024-40766) and weak password hygiene. Migrating from Gen 6 to Gen 7 without resets? That’s leaving doors wide open. Full details + what to

    @TheHackersNews

    7 Aug 2025

    10636 Impressions

    24 Retweets

    60 Likes

    12 Bookmarks

    1 Reply

    1 Quote

  43. 🚨 Attackers are hitting SonicWall firewalls again—but it’s not a new zero-day. Turns out, they’re exploiting a known bug (CVE-2024-40766) and weak password hygiene. Migrating from Gen 6 to Gen 7 without resets? That’s leaving doors wide open. Full... https://t.co/gC

    @IT_news_for_all

    7 Aug 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. موجة هجمات فدية جديدة تستهدف SonicWall، وتكشف التقارير استغلال محتمل لثغرة يوم صفر في SonicOS لتوزيع برمجية Akira. -الهجمات طالت أجهزة محدثة وتستخدم MFA - الهجمات بد

    @cyberscastx

    4 Aug 2025

    1761 Impressions

    2 Retweets

    10 Likes

    2 Bookmarks

    3 Replies

    0 Quotes

  45. 🚨 Ransomware on the Rise! December 2024 saw a record-breaking 621 victims of ransomware attacks. New groups like FunkSec & SafePay are gaining momentum, while old players like Akira exploit vulnerabilities like CVE-2024-40766. Protect your organization NOW! 🛡️ https://t.co

    @QnATech

    16 Jan 2025

    66 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. #Malware #Vulnerability Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766 https://t.co/UtKzhVf5rC

    @Komodosec

    9 Jan 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Threat Alert: SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in Son CVE-2024-40766 Severity: ⚠️ Critical Maturity: 💥 Mainstream Learn more: https://t.co/rOv4wJ1kn7 #CyberSecurity #ThreatIntel #InfoSec (1/3)

    @fletch_ai

    9 Jan 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  48. Over 48,000 SonicWall devices remain vulnerable to a critical security flaw, exposing organizations worldwide to ransomware attacks. The vulnerability, identified as CVE-2024-40766, was first disclosed in September 2024. #Ransomware #CyberSecurityAwareness #MalwareAlert #Hack ht

    @techaniruddh

    7 Jan 2025

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. Additional Evidence of SonicWall CVE-2024-40766 Exploitation by Akira and Fog, and Patch Progress - Security Research Center Blog #vuln #akira #fog https://t.co/FtRYB1tfHH

    @johntheMAT

    27 Dec 2024

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Additional Evidence of SonicWall CVE-2024-40766 Exploitation by Akira and Fog, and Patch Progress - Security Research Center Blog https://t.co/fxXQ8bC5lZ

    @anemone_fish

    27 Dec 2024

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.