← Back to browse · API

CVE-2024-40766

Severity
CRITICAL
CVSS
9.3
EPSS
0.18177
Risk score
68.56
CISA KEV
Yes
PoC
No
Published
2024-08-23
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-38613, GHSA-8736-PR6R-R9HR
Products
SonicWall:SonicOS, SonicWall:SonicOS 5.9.2.14-12o and older versions, SonicWall:SonicOS 6.5.4.14-109n and older versions, SonicWall:SonicOS 7.0.1-5035 and older versions
Sources
cisa.gov CVE-2024-40766
euvd EUVD-2024-38613

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

References