CVE-2024-40766

Published Aug 23, 2024

Last updated a year ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-40766 is an improper access control vulnerability found in SonicWall SonicOS. The vulnerability lies in the SonicOS management access, potentially leading to unauthorized resource access. In specific conditions, this can cause the firewall to crash. The vulnerability affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. It is recommended to restrict firewall management access to trusted sources and ensure that firewall WAN management is not accessible from the public internet. Similarly, limiting SSLVPN access to trusted sources or disabling it from the internet is also advised.

Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Source
PSIRT@sonicwall.com
NVD status
Analyzed
Products
sonicos

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SonicWall SonicOS Improper Access Control Vulnerability
Exploit added on
Sep 9, 2024
Exploit action due
Sep 30, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
PSIRT@sonicwall.com
CWE-284

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    10 Aug 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. #VeilleCyber : 📱 #Bouygues : 6,4M clients exposés (IBAN, coordonnées) 🖥️ Millions de PC #Dell vulnérables aux backdoors #ReVault ✈️ #AirFranceKLM : fuite CRM par #ShinyHunters 🔐 #SonicWall : attaques sur CVE-2024-40766 Détails et conseils 👇 https://t.co/PNV

    @VeilleCyber_fr

    10 Aug 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. SonicWall has dismissed zero-day vulnerability fears after investigating recent ransomware attacks, confirming they stem from the known flaw CVE-2024-40766, urging users to update firmware and reset passwords for improved security. #Cybersecurity #Ransom… https://t.co/kCZQAMfKd

    @Cyber_O51NT

    9 Aug 2025

    264 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. SonicWall says that recent Akira ransomware attacks exploiting Gen 7 firewalls with SSLVPN enabled are exploiting an older vulnerability rather than a zero-day flaw. The company says that the attackers are targeting CVE-2024-40766, fixed in August 2024. https://t.co/OiXMymOkGF ht

    @riskigy

    8 Aug 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. #sonicwall says recent Gen 7 firewall hacks were not a zero-day but exploited CVE-2024-40766, tied to reused legacy passwords during migrations. Fewer than 40 confirmed cases, with Akira ransomware deployed. Users urged to update and reset credentials. https://t.co/eVP2kVNdhC

    @Prevent_Cyber

    8 Aug 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. SonicWall confirms no zero-day vulnerabilities are being exploited despite reports of targeted ransomware attacks linked to CVE-2024-40766. Weak password management during device migration facilitated the breaches. #CyberDefense #Ransomware #Japan https://t.co/rT85TfKOaX

    @TweetThreatNews

    7 Aug 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. #SonicWall updated its advisory on the recent campaign against its firewalls, claiming the incidents are likely tied to the exploitation of CVE-2024-40766 and not a new bug They are investigating about 40 incidents https://t.co/R9A2sCHPhj

    @jgreigj

    7 Aug 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 SonicWall Vulnerability Exploited in August Akira Campaign Recent Akira ransomware intrusions have been linked to CVE-2024-40766, a previously disclosed vulnerability affecting SonicWall firewall appliances. Initial reporting suggested the possibility of a zero-day https://

    @mox_five

    7 Aug 2025

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. SonicWall confirmed that recent attacks on its Gen 7 firewalls with SSL VPN are linked to CVE-2024-40766, a patched vulnerability (CVSS score: 9.3) related to improper access control. https://t.co/MgAdr2D927

    @securityRSS

    7 Aug 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 📌 سونيك وول أكدت أن الهجمات الأخيرة على جدران الحماية من الجيل السابع وما فوق المتعلقة بـ SSL VPN ناتجة عن ثغرة قديمة تم تصحيحها وإعادة استخدام كلمات المرور

    @Cybercachear

    7 Aug 2025

    41 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 Attackers are hitting SonicWall firewalls again—but it’s not a new zero-day. Turns out, they’re exploiting a known bug (CVE-2024-40766) and weak password hygiene. Migrating from Gen 6 to Gen 7 without resets? That’s leaving doors wide open. Fu... https://t.co/zf

    @IT_news_for_all

    7 Aug 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 Attackers are hitting SonicWall firewalls again—but it’s not a new zero-day. Turns out, they’re exploiting a known bug (CVE-2024-40766) and weak password hygiene. Migrating from Gen 6 to Gen 7 without resets? That’s leaving doors wide open. Full details + what to

    @TheHackersNews

    7 Aug 2025

    10636 Impressions

    24 Retweets

    60 Likes

    12 Bookmarks

    1 Reply

    1 Quote

  13. 🚨 Attackers are hitting SonicWall firewalls again—but it’s not a new zero-day. Turns out, they’re exploiting a known bug (CVE-2024-40766) and weak password hygiene. Migrating from Gen 6 to Gen 7 without resets? That’s leaving doors wide open. Full... https://t.co/gC

    @IT_news_for_all

    7 Aug 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. موجة هجمات فدية جديدة تستهدف SonicWall، وتكشف التقارير استغلال محتمل لثغرة يوم صفر في SonicOS لتوزيع برمجية Akira. -الهجمات طالت أجهزة محدثة وتستخدم MFA - الهجمات بد

    @cyberscastx

    4 Aug 2025

    1761 Impressions

    2 Retweets

    10 Likes

    2 Bookmarks

    3 Replies

    0 Quotes

  15. 🚨 Ransomware on the Rise! December 2024 saw a record-breaking 621 victims of ransomware attacks. New groups like FunkSec & SafePay are gaining momentum, while old players like Akira exploit vulnerabilities like CVE-2024-40766. Protect your organization NOW! 🛡️ https://t.co

    @QnATech

    16 Jan 2025

    66 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. #Malware #Vulnerability Thousands of SonicWall Devices Remain Vulnerable to CVE-2024-40766 https://t.co/UtKzhVf5rC

    @Komodosec

    9 Jan 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Threat Alert: SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in Son CVE-2024-40766 Severity: ⚠️ Critical Maturity: 💥 Mainstream Learn more: https://t.co/rOv4wJ1kn7 #CyberSecurity #ThreatIntel #InfoSec (1/3)

    @fletch_ai

    9 Jan 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. Over 48,000 SonicWall devices remain vulnerable to a critical security flaw, exposing organizations worldwide to ransomware attacks. The vulnerability, identified as CVE-2024-40766, was first disclosed in September 2024. #Ransomware #CyberSecurityAwareness #MalwareAlert #Hack ht

    @techaniruddh

    7 Jan 2025

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Additional Evidence of SonicWall CVE-2024-40766 Exploitation by Akira and Fog, and Patch Progress - Security Research Center Blog #vuln #akira #fog https://t.co/FtRYB1tfHH

    @johntheMAT

    27 Dec 2024

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Additional Evidence of SonicWall CVE-2024-40766 Exploitation by Akira and Fog, and Patch Progress - Security Research Center Blog https://t.co/fxXQ8bC5lZ

    @anemone_fish

    27 Dec 2024

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. AkiraとFogによるSonicWall CVE-2024-40766悪用の追加証拠とパッチの進捗状況の記事を書きました。 『Additional Evidence of SonicWall CVE-2024-40766 Exploitation by Akira and Fog, and Patch Progress』 https://t.co/K3BW5jwffd

    @nekono_naha

    27 Dec 2024

    1645 Impressions

    5 Retweets

    16 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  22. SonicWall SSLVPN access control flaw is now exploited in attacks SonicWall is warning that a recently fixed access control flaw tracked as CVE-2024-40766 in SonicOS is now "potentially" exploited in attacks, urging admins to apply patches as soon as po... https://t.co/DzZwTl6WET

    @SecurityAid

    22 Dec 2024

    27 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  23. 印象に残った2024年の公開サーバ脆弱性まとめ。脆弱性大賞は1位 Ivanti、2位Palo Alto、3位Fortinet。審査員特別賞は SonicWall CVE-2024-40766です。私の調べではAkiraとFogによる被害組織が100を超えてますがどのベンダも脆弱性悪用を断言できておらず大変後味が悪いため。 所感:… https://t.co/fXdM81wJQr https://t.co/dn1z3YfVvQ

    @nekono_naha

    19 Dec 2024

    9200 Impressions

    33 Retweets

    136 Likes

    59 Bookmarks

    0 Replies

    2 Quotes

  24. 【独自】ランサムウェア活動で、Array Networks AG/vxAGの脆弱性CVE-2023-28461と、SonicWall SonicOSの脆弱性CVE-2024-40766がそれぞれ悪用された模様。米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログが更新。 https://t.co/8OLgYfFXPf

    @__kokumoto

    2 Dec 2024

    1483 Impressions

    2 Retweets

    10 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  25. Fog & Akira ransomware groups are exploiting the critical CVE-2024-40766 vulnerability in SonicWall VPN systems, targeting enterprises and critical infrastructure. Protect your systems with the latest patch. https://t.co/ti9a9cUFQP

    @Shift6Security

    25 Nov 2024

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Zunahme von Fog- und Akira-Ransomware Im September gab SonicWall bekannt, dass CVE-2024-40766 aktiv ausgenutzt wird. #available_in_English #Akira #ArcticWolf #Fog #Ransomware https://t.co/CETHYkcDhD https://t.co/1wCgmLjCFb

    @B2bCyber

    23 Nov 2024

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    23 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  28. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    19 Nov 2024

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    18 Nov 2024

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  30. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    17 Nov 2024

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    10 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  32. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    8 Nov 2024

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  33. #Fog and #Akira #ransomware attacks #exploit #SonicWall #VPN #Vulnerabilities #flaw CVE-2024-40766 https://t.co/04lXKFoF3k https://t.co/f2e8oJa19p

    @omvapt

    7 Nov 2024

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    5 Nov 2024

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. CVE-2024-40766

    @WakeUpDeath

    4 Nov 2024

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  36. آسیب پذیری جدیدی با کد شناسایی CVE-2024-40766 برای محصول SonicWall VPN منتشر شده است. باج افزارها، از آسیب پذیری ها برای گرفتن دسترسی به سیستم های قربانی ، استفاده می کنند. باج افزارهای FoG و Akira از آسیب پذیری SonicWall VPN استفاده می کنند. https://t.co/Y2P1U3epiq https://t.

    @AmirHossein_sec

    1 Nov 2024

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Fog ransomware e Akira: attacco ai sistemi VPN SonicWall Sicurezza Informatica, accesso iniziale, Akira, CVE-2024-40766, cybercrime, Fog ransomware, sonicwall, VPN, vulnerabilità https://t.co/JJrtubWtQU https://t.co/SmYT4r2qxG

    @matricedigitale

    31 Oct 2024

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Hackers are exploiting a vulnerability in #SonicWall #VPN to launch ransomware attacks using the Fog and Akira strains. CVE-2024-40766 https://t.co/2zdhqQXeCE

    @the_yellow_fall

    30 Oct 2024

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. SonicWall vulnerability CVE-2024-40766 exploited in Ransomware attacks #Sonicwall #CVE-2024-40766 #FogRansomware #AkiraRansomware https://t.co/uxLT25Fc8p

    @pravin_karthik

    30 Oct 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Хакерские группировки Akira и Fog объединили усилия для проведения атак, используя уязвимость в VPN-системах SonicWall. Недавно обнаруженная уязвимость CVE-2024-40766 в системе SSL VPN открыла двери для незаконного доступа к корпоративным сетям: https://t.co/Nh9Vl0NJoy #Akira ht

    @infosecmedia_

    29 Oct 2024

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw fixed in August 2024. https://t.co/ErEdEHwkHe https://t.co/BBcU

    @riskigy

    29 Oct 2024

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. Hackers Use Fog Ransomware To Attack SonicWall VPNs And Breach Corporate Networks: Recent cyberattacks involving Akira and Fog threat actors have targeted various industries, exploiting a vulnerability (CVE-2024-40766) in SonicWall SSL VPN devices, where… https://t.co/dRikXpc4SH

    @shah_sheikh

    29 Oct 2024

    177 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  43. Fog and Akira ransomware operators are exploiting the SonicWall VPN flaw CVE-2024-40766, prompting SonicWall to urge affected users to apply patches to prevent unauthorized access and potential firewall crashes. #CyberSecurity #Ransomware https://t.co/NucrwWDCRo

    @Cyber_O51NT

    29 Oct 2024

    497 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Fog and Akira ransomware attacks exploit SonicWall VPN flaw CVE-2024-40766 https://t.co/Wcpr3hajqS #BreakingNews https://t.co/EiI9BdqIyf

    @evanderburg

    29 Oct 2024

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Fog and Akira ransomware attacks exploit SonicWall VPN flaw CVE-2024-40766: Fog and Akira ransomware operators are exploiting SonicWall VPN flaw CVE-2024-40766 to breach enterprise networks. Fog and Akira ransomware operators are exploiting the critical… https://t.co/e5SSCeFui1 h

    @shah_sheikh

    29 Oct 2024

    46 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Fog ransomware targets SonicWall VPNs to breach corporate networks: https://t.co/hqg01Y2Kr7 Fog and Akira ransomware are exploiting a critical SSL VPN access control flaw (CVE-2024-40766) in SonicWall VPNs to breach corporate networks. SonicWall patched the flaw in August 2024,…

    @securityRSS

    29 Oct 2024

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw. https://t.co/8NJFgZjG4l

    @blackwired32799

    28 Oct 2024

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. A critical vulnerability in SonicWall VPN devices is being exploited by Akira and Fog ransomware groups, compromising corporate networks. 🚨 CVE-2024-40766 - CVSS: 9.8 168,000 SonicWall endpoints remain vulnerable to the CVE-2024-40766 vulnerability (Security researcher Yutaka…

    @cytexsmb

    28 Oct 2024

    576 Impressions

    4 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    3 Quotes

  49. #NEW #SHARE Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw. https://t.co/z7XyXk8vi0

    @CyberSysblue

    28 Oct 2024

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🚨威胁警报!使用CVE-2024-40766通过SonicWall VPN账户侵入企业网络,Akira和Fog勒索软件操作合作。确保及时打补丁,启用多因素认证,密切监控VPN访问!#网络安全#SonicWall#VPN#勒索软件🛡️💻 https://t.co/9tL3yNuf8u

    @cverc_cn2

    28 Oct 2024

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.