EXPOSURES › CVE-2024-40766
CVE-2024-40766
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSonicWall SonicOS improper access control flaw allowed unauthorized resource access and potential crashes, linked to ransomware.
SonicWall SonicOS suffered an improper access control vulnerability enabling unauthorized access and system crashes, directly tied to ransomware activity. DIB organizations must ensure their network perimeter devices are patched against actively exploited flaws to prevent similar breaches. This failure highlights the critical need for continuous patch management on security hardware.
Shame score — The flaw was actively exploited in the wild and linked to ransomware, indicating severe negligence and avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.