CVE-2024-40766

CRITICAL(9.8)KEVRansomwareErhöhtes Risiko

SonicWall SonicOS Improper Access Control Vulnerability

Beschreibung

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

KEV-Informationen

Hersteller
SonicWall
Produkt
SonicOS
Hinzugefügt am
9. September 2024
Fälligkeitsdatum
30. September 2024
Erforderliche Maßnahme
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
3.9
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
sonicwallsonicos< 5.9.2.14-13o; < 6.5.2.8-2n; < 6.5.4.15.116n; <= 7.0.1-5035

Mehrere CVSS-Bewertungen

Quelle: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.3
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Referenzen

CVSS-Score

9.8
CRITICAL(9.8)

EPSS-Score

EPSS-Score15.59%
EPSS-Perzentil96.5%

Daten

Veröffentlicht23. August 2024
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.