CVE-2024-53705

Published Jan 9, 2025

Last updated 2 months ago

Overview

Description
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
Source
PSIRT@sonicwall.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity
HIGH

Weaknesses

PSIRT@sonicwall.com
CWE-918

Social media

Hype score
Not currently trending
  1. Threat Alert: SonicWall tells admins to patch worrying SSLVPN flaw immediately CVE-2024-53704 CVE-2024-40762 CVE-2024-53705 Severity: 🔴 High Maturity: 🧨 Trending Learn more: https://t.co/BE7rIxijE6 #CyberSecurity #ThreatIntel #InfoSec

    @fletch_ai

    10 Jan 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2024-53704,CVE-2024-40762,CVE-2024-53705,CVE-2024-53706 alert 🚨 SonicWall improper authentication vulnerability in the SSLVPN The vulnerability is actively exploited in the wild and has been integrated into Patrowl. Our customers assets are protected. 🦉 #CyberSec #SonicWall

    @Patrowl_io

    9 Jan 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-53705 SSRF Flaw in SonicOS SSH Enables Unauthorized TCP Connection Son... https://t.co/KHpByg9ybi Customizable Vulnerability Alerts: https://t.co/U7998fz7yk

    @VulmonFeeds

    9 Jan 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2024-53705 A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any por… https://t.co/pdx8mwllaJ

    @CVEnew

    9 Jan 2025

    173 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨🚨CVE-2024-40762, CVE-2024-53704, CVE-2024-53705, CVE-2024-53706: SonicWall Issues Important Security Advisory for Multiple Vulnerabilities in SonicOS ZoomEye Dork👉banner="SonicOS" 48k+ results are found on ZoomEye. ZoomEye Link: https://t.co/BBGCGDPXCA Refer:… https://t.co

    @zoomeye_team

    8 Jan 2025

    87 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes