SonicWall has announced a serious security flaw in its SonicOS management interface, tracked as CVE-2024-40766.
This vulnerability, categorized as improper access control (CWE-284), has received a high-risk rating of 9.3 on the CVSS v3 scale. It poses considerable threats, potentially granting unauthorized access to system resources and, in some cases, causing the firewall to malfunction.
SonicWall’s advisory notes, “A significant improper access control issue has been detected in SonicWall SonicOS management access. This could lead to unauthorized access to system resources and, under certain conditions, might result in a firewall crash.”
The flaw affects a wide range of SonicWall devices across various generations. It impacts Gen 5 models, including SOHO units with firmware versions up to 5.9.2.14-12o. Gen 6 devices are also at risk, including SOHOW, TZ, NSA, and SM series firewalls with firmware versions up to 6.5.4.14-109n. Gen 7 devices, like TZ, NSa, and NSsp series, running SonicOS versions up to 7.0.1-5035 are similarly affected. SonicWall urges users to upgrade to the most recent firmware versions to address these vulnerabilities.

To mitigate potential risks, SonicWall advises limiting firewall management access to trusted sources only or disabling WAN management access from the Internet. Detailed instructions on how to restrict SonicOS admin access can be found through SonicWall’s support resources. Users should promptly install the latest patches available on mysonicwall.com and reach out to SonicWall Technical Support for additional help if needed.

SonicWall has issued firmware updates to rectify this issue: Gen 5 devices should be upgraded to version 5.9.2.14-13o, while Gen 6 devices can use versions like 6.5.2.8-2n or 6.5.4.15.116n, depending on the model. For Gen 7 devices, ensure that the firmware is updated beyond version 7.0.1-5035.
SonicWall’s quick action highlights its dedication to maintaining strong security for its products. Users should remain vigilant about firmware updates and adhere to best practices for network protection. For further details and to access the latest firmware updates, visit SonicWall’s official website or contact their support team.
This advisory emphasizes the critical importance of regularly updating and properly configuring network security devices to avoid unauthorized access and service interruptions.



