Update on Firewall Vulnerability: SonicWall Releases Critical Patch to Prevent Unauthorized Access
SonicWall has issued patches to fix a critical weakness affecting its firewalls that, if exploited, could allow unauthorized individuals to gain access to the devices.
The flaw, known as CVE-2024-40766 (CVSS score: 9.3), is categorized as an inappropriate access control vulnerability.
“A vulnerability associated with improper access control has been discovered in the SonicWall SonicOS management access, potentially opening the door for unauthorized entry to resources and in certain scenarios, leading to system crashes,” according to a recent advisory from the company announced last week.
“The affected devices include SonicWall Firewall Gen 5 and Gen 6, as well as Gen 7 systems with SonicOS 7.0.1-5035 and earlier versions.”
The affected versions include –
- SOHO (Gen 5 Firewalls) – 5.9.2.14-13o
- Gen 6 Firewalls – 6.5.2.8-2n (for SM9800, NSsp 12400, and NSsp 12800) and 6.5.4.15.116n (for other Gen 6 Firewall appliances)
SonicWall stated that the vulnerability does not occur in SonicOS firmware versions above 7.0.1-5035, but users are encouraged to install the most recent firmware as a precautionary measure.
While the vendor of networking equipment does not report any active exploitation of this vulnerability, it is crucial for users to promptly apply the updates to shield against potential risks.
In the previous year, Mandiant, a Google-owned entity, unveiled that a suspected threat actor associated with China, designated as UNC4540, targeted vulnerable SonicWall Secure Mobile Access (SMA) 100 appliances to deploy Tiny SHell and create persistent entry.

Various clusters of Chinese-linked cyber operations have shifted their focus to target edge infrastructures to infiltrate systems and establish undisturbed remote access.
This includes Velvet Ant, an intrusion group that was recently identified using a zero-day exploit against Cisco Switch appliances to propagate a new form of malware known as VELVETSHELL, a customized blend of Tiny SHell and 3proxy.

