CVE-2024-40766
קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- SonicWall SonicOS Improper Access Control Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 18% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-284
מוצרים מושפעים
sonicwall: sonicos; sonicwall: soho; sonicwall: nssp 12400; sonicwall: nssp 12800; sonicwall: sm9800; sonicwall: nsa 2650; sonicwall: nsa 3600; sonicwall: nsa 3650; sonicwall: nsa 4600; sonicwall: nsa 4650; sonicwall: nsa 5600; sonicwall: nsa 5650; sonicwall: nsa 6600; sonicwall: nsa 6650; sonicwall: sm 9200
קישורים
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource