Skip to content
COOEY

EXPOSURES › CVE-2024-53704

CVE-2024-53704

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-02-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-53704 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatchedauth-bypass

SonicWall SonicOS SSLVPN bypassed authentication allowing remote attackers to bypass login.

A remote attacker could bypass authentication on SonicWall SonicOS SSLVPN, enabling unauthorized access to networks. DIB orgs must ensure SSLVPN configurations are patched and monitored, as this flaw directly undermines access controls and could lead to data exfiltration or ransomware deployment.

Shame score — An authentication bypass in a widely deployed firewall/VPN product is highly avoidable and directly enables lateral movement and data theft.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.