CVE-2024-40766

Published Aug 23, 2024

Last updated 2 months ago

Overview

Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Source
PSIRT@sonicwall.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
SonicWall SonicOS Improper Access Control Vulnerability
Exploit added on
Sep 9, 2024
Exploit action due
Sep 30, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-noinfo
PSIRT@sonicwall.com
CWE-284

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    10 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    8 Nov 2024

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. #Fog and #Akira #ransomware attacks #exploit #SonicWall #VPN #Vulnerabilities #flaw CVE-2024-40766 https://t.co/04lXKFoF3k https://t.co/f2e8oJa19p

    @omvapt

    7 Nov 2024

    113 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Actively exploited CVE : CVE-2024-40766

    @transilienceai

    5 Nov 2024

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CVE-2024-40766

    @WakeUpDeath

    4 Nov 2024

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. آسیب پذیری جدیدی با کد شناسایی CVE-2024-40766 برای محصول SonicWall VPN منتشر شده است. باج افزارها، از آسیب پذیری ها برای گرفتن دسترسی به سیستم های قربانی ، استفاده می کنند. باج افزارهای FoG و Akira از آسیب پذیری SonicWall VPN استفاده می کنند. https://t.co/Y2P1U3epiq https://t.

    @AmirHossein_sec

    1 Nov 2024

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Fog ransomware e Akira: attacco ai sistemi VPN SonicWall Sicurezza Informatica, accesso iniziale, Akira, CVE-2024-40766, cybercrime, Fog ransomware, sonicwall, VPN, vulnerabilità https://t.co/JJrtubWtQU https://t.co/SmYT4r2qxG

    @matricedigitale

    31 Oct 2024

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Hackers are exploiting a vulnerability in #SonicWall #VPN to launch ransomware attacks using the Fog and Akira strains. CVE-2024-40766 https://t.co/2zdhqQXeCE

    @the_yellow_fall

    30 Oct 2024

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. SonicWall vulnerability CVE-2024-40766 exploited in Ransomware attacks #Sonicwall #CVE-2024-40766 #FogRansomware #AkiraRansomware https://t.co/uxLT25Fc8p

    @pravin_karthik

    30 Oct 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Хакерские группировки Akira и Fog объединили усилия для проведения атак, используя уязвимость в VPN-системах SonicWall. Недавно обнаруженная уязвимость CVE-2024-40766 в системе SSL VPN открыла двери для незаконного доступа к корпоративным сетям: https://t.co/Nh9Vl0NJoy #Akira ht

    @infosecmedia_

    29 Oct 2024

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw fixed in August 2024. https://t.co/ErEdEHwkHe https://t.co/BBcU

    @riskigy

    29 Oct 2024

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Hackers Use Fog Ransomware To Attack SonicWall VPNs And Breach Corporate Networks: Recent cyberattacks involving Akira and Fog threat actors have targeted various industries, exploiting a vulnerability (CVE-2024-40766) in SonicWall SSL VPN devices, where… https://t.co/dRikXpc4SH

    @shah_sheikh

    29 Oct 2024

    177 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  13. Fog and Akira ransomware operators are exploiting the SonicWall VPN flaw CVE-2024-40766, prompting SonicWall to urge affected users to apply patches to prevent unauthorized access and potential firewall crashes. #CyberSecurity #Ransomware https://t.co/NucrwWDCRo

    @Cyber_O51NT

    29 Oct 2024

    497 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Fog and Akira ransomware attacks exploit SonicWall VPN flaw CVE-2024-40766 https://t.co/Wcpr3hajqS #BreakingNews https://t.co/EiI9BdqIyf

    @evanderburg

    29 Oct 2024

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Fog and Akira ransomware attacks exploit SonicWall VPN flaw CVE-2024-40766: Fog and Akira ransomware operators are exploiting SonicWall VPN flaw CVE-2024-40766 to breach enterprise networks. Fog and Akira ransomware operators are exploiting the critical… https://t.co/e5SSCeFui1 h

    @shah_sheikh

    29 Oct 2024

    46 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Fog ransomware targets SonicWall VPNs to breach corporate networks: https://t.co/hqg01Y2Kr7 Fog and Akira ransomware are exploiting a critical SSL VPN access control flaw (CVE-2024-40766) in SonicWall VPNs to breach corporate networks. SonicWall patched the flaw in August 2024,…

    @securityRSS

    29 Oct 2024

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw. https://t.co/8NJFgZjG4l

    @blackwired32799

    28 Oct 2024

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. A critical vulnerability in SonicWall VPN devices is being exploited by Akira and Fog ransomware groups, compromising corporate networks. 🚨 CVE-2024-40766 - CVSS: 9.8 168,000 SonicWall endpoints remain vulnerable to the CVE-2024-40766 vulnerability (Security researcher Yutaka…

    @cytexsmb

    28 Oct 2024

    576 Impressions

    4 Retweets

    4 Likes

    0 Bookmarks

    0 Replies

    3 Quotes

  19. #NEW #SHARE Fog and Akira ransomware operators are increasingly breaching corporate networks through SonicWall VPN accounts, with the threat actors believed to be exploiting CVE-2024-40766, a critical SSL VPN access control flaw. https://t.co/z7XyXk8vi0

    @CyberSysblue

    28 Oct 2024

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨威胁警报!使用CVE-2024-40766通过SonicWall VPN账户侵入企业网络,Akira和Fog勒索软件操作合作。确保及时打补丁,启用多因素认证,密切监控VPN访问!#网络安全#SonicWall#VPN#勒索软件🛡️💻 https://t.co/9tL3yNuf8u

    @cverc_cn2

    28 Oct 2024

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Arctic Wolf has reported a notable increase in incidents involving the Akira/Fog ransomware, believed to be exploiting SonicWall’s CVE-2024-40766 vulnerability. In response, we investigated the status of patch applications. As of the survey conducted on October 23, of the… https

    @nekono_naha

    28 Oct 2024

    1425 Impressions

    4 Retweets

    8 Likes

    4 Bookmarks

    1 Reply

    1 Quote

  22. Arctic Wolf社がSonicWallのCVE-2024-40766を悪用したと考えられるAkira/Fogランサム事案の顕著な増加を観測したとのことでパッチ適用の状況を調査しました。 10月23日の調査ではグローバルでの公開SocniWallの42万台中、少なくとも40%… https://t.co/CZ5qxewEqZ https://t.co/ku0Qxup7eZ

    @nekono_naha

    28 Oct 2024

    2674 Impressions

    6 Retweets

    27 Likes

    7 Bookmarks

    1 Reply

    0 Quotes

  23. Fog and Akira ransomware operators are targeting corporate networks via SonicWall VPN accounts, likely exploiting the critical SSL VPN vulnerability CVE-2024-40766. https://t.co/nnXQTBr4Mt #fog #AKIRA #Ransomware #sonicwall #CyberSecurity #threatresq

    @ThreatResq

    28 Oct 2024

    72 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  24. Fog ransomware is exploiting SonicWall VPN vulnerabilities (CVE-2024-40766) to breach corporate networks, often bypassing security due to unpatched software and lack of multi-factor authentication. Attackers gain access quickly and encrypt data, targeting VMs and backups. Akira…

    @darkintellink

    28 Oct 2024

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. "Akira" and "Fog" ransomware are exploiting CVE-2024-40766, a Critical Improper Access Control Vulnerability in SonicWall devices (Base Score: 9.8 CRITICAL), affects SonicWall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. They… h

    @Ransom_DB

    27 Oct 2024

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. "Akira" and "Fog" ransomware are exploiting CVE-2024-40766, a Critical Improper Access Control Vulnerability in SonicWall devices (Base Score: 9.8 CRITICAL), affects SonicWall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. They… h

    @Ransom_DB

    27 Oct 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. "Akira" and "Fog" ransomware are exploiting CVE-2024-40766, a Critical Improper Access Control Vulnerability in SonicWall devices (Base Score: 9.8 CRITICAL), affects SonicWall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. They… h

    @Ransom_DB

    27 Oct 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 📌 تستهدف برمجيات فدية فوغ وآكيرا ثغرة حرجة في جدران الحماية SonicWall، مما يسمح بالوصول غير المصرح به عبر ميزة SSL VPN. تمثل الثغرة CVE-2024-40766 تهديدًا متزايدًا للشبكات المؤسسية، مما يستدعي اتخاذ تدابير أمنية فورية. https://t.co/S63cUiNZgJ

    @cyberetweet

    27 Oct 2024

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. #ITSecurity CVE-2024-40766 https://t.co/dwi6nAAoXy

    @seaarepea

    27 Oct 2024

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 Fog & Akira Ransomware Alert 🚨 New ransomware attacks are targeting corporate networks via SonicWall VPNs, exploiting the CVE-2024-40766 flaw. 🔑 Key Tips: 1. Patch SonicWall ASAP🛠️ 2. Enable Multi-Factor Authentication (MFA)🔒 3. Monitor VPN Access Logs📊 #CyberSecu

    @shaharia_munna

    27 Oct 2024

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Fog及びAkiraの両ランサムウェアのオペレータが、SonicWall VPNのアカウントを使用して企業に侵入している。Arctic Wolf社報告。SSL VPNのアクセス制御脆弱性CVE-2024-40766を使用しているとみられる。少なくとも30の侵入事案が発生。2集団はインフラも共有している模様。 https://t.co/1gCsvgMYMJ

    @__kokumoto

    27 Oct 2024

    1325 Impressions

    4 Retweets

    9 Likes

    2 Bookmarks

    0 Replies

    1 Quote

  32. Akira Ransomware Exploit CVE-2024-40766 in SonicWall SonicOS Discover the latest tactics of the Akira ransomware group and how they have evolved to target both #Windows and #Linux hosts. https://t.co/1gQjaBMJCn

    @the_yellow_fall

    22 Oct 2024

    321 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations