{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-40766","assignerOrgId":"44b2ff79-1416-4492-88bb-ed0da00c7315","state":"PUBLISHED","assignerShortName":"sonicwall","dateReserved":"2024-07-10T15:58:49.462Z","datePublished":"2024-08-23T06:19:07.229Z","dateUpdated":"2025-10-21T22:55:46.444Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unknown","platforms":["Gen5","Gen6","Gen7"],"product":"SonicOS","vendor":"SonicWall","versions":[{"status":"affected","version":"5.9.2.14-12o and older versions"},{"status":"affected","version":"6.5.4.14-109n and older versions"},{"status":"affected","version":"7.0.1-5035 and older versions"}]}],"datePublic":"2024-08-23T06:13:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions."}],"value":"An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"44b2ff79-1416-4492-88bb-ed0da00c7315","shortName":"sonicwall","dateUpdated":"2024-08-23T06:19:07.229Z"},"references":[{"tags":["vendor-advisory"],"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015"}],"source":{"advisory":"SNWLID-2024-0015","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"CHANGED","version":"3.1","baseScore":9.3,"attackVector":"NETWORK","baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"LOW","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"id":"CVE-2024-40766","role":"CISA Coordinator","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-09T14:11:51.602153Z"}}},{"other":{"type":"kev","content":{"dateAdded":"2024-09-09","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-40766"}}}],"affected":[{"cpes":["cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*"],"vendor":"sonicwall","product":"sonicos","versions":[{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"5.9.2.14-12o"},{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"6.5.4.14-109n"},{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"7.0.1-5035"}],"defaultStatus":"unknown"},{"cpes":["cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*"],"vendor":"sonicwall","product":"sonicos","versions":[{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"5.9.2.14-12o"},{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"6.5.4.14-109n"},{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"7.0.1-5035"}],"defaultStatus":"unknown"},{"cpes":["cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*"],"vendor":"sonicwall","product":"sonicos","versions":[{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"5.9.2.14-12o"},{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"6.5.4.14-109n"},{"status":"affected","version":"0","versionType":"custom","lessThanOrEqual":"7.0.1-5035"}],"defaultStatus":"unknown"}],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-40766","tags":["government-resource"]}],"timeline":[{"time":"2024-09-09T00:00:00.000Z","lang":"en","value":"CVE-2024-40766 added to CISA KEV"}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-21T22:55:46.444Z"}}]}}