Back to Blog
CVE-2024-40766: SonicWall SonicOS — Ransomware via Firewall Exploit (September 2024)
vulnerabilities

CVE-2024-40766: SonicWall SonicOS — Ransomware via Firewall Exploit (September 2024)

breachwire TeamJun 24, 20262 min read

CVE-2024-40766 — SonicWall SonicOS

CVE-2024-40766 (critical) is being actively exploited by ransomware groups Akira and Fog to gain unauthorized access to SonicWall SonicOS firewalls. Attackers leverage this vulnerability, along with CVE-2024-12802 (MFA bypass), to compromise thousands of organizations globally. The flaw enables remote attackers to bypass authentication controls and deploy ransomware within hours, often before defenders can respond.

Attack Vector

Attackers scan for exposed SonicWall SSLVPN services running vulnerable SonicOS firmware. Using CVE-2024-40766, they bypass authentication and escalate privileges, often exploiting weak or default credentials and poor configuration. In some cases, attackers leverage CVE-2024-12802 to bypass multi-factor authentication, and exploit a related SonicWall cloud backup breach to retrieve encrypted credentials, maintaining persistent access. Once inside, adversaries rapidly deploy ransomware, encrypting systems and sometimes locking out administrators from perimeter devices.

Who Is at Risk

All organizations running SonicWall firewalls with SSLVPN enabled and unpatched SonicOS firmware are at immediate risk. Multiple hardware generations are affected. Global targeting has been observed, with thousands of organizations compromised since September 2024. Firms with insufficient credential management or incomplete patching remain especially vulnerable. No sector is exempt; both public and private entities have been impacted.

Patch & Mitigate

  • Patch: Apply the latest SonicOS firmware updates addressing CVE-2024-40766 and CVE-2024-12802 immediately. Confirm patch status on all perimeter devices.
  • Workaround: Disable SSLVPN services if patching is delayed. Enforce strong, unique credentials and review all firewall configurations.
  • Detect: Monitor for anomalous VPN logins, failed authentication attempts, and unexpected administrative actions. Check for signs of credential theft and unauthorized configuration changes in firewall logs.

MITRE ATT&CK

  • TA0006 — Credential Access: Attackers steal or reuse credentials via exposed backups and weak management.
  • TA0007 — Discovery: Adversaries enumerate network and device configurations post-compromise.
  • TA0003 — Persistence: Use of stolen credentials and MFA bypass to maintain long-term access.

Source: https://isc.sans.edu/diary/rss/33094

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: