CISA Known Exploited Vulnerability (KEV)
SonicWall SonicOS Improper Access Control Vulnerability
September 9, 2024
September 30, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-284 |
Improper Access Control |