⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.. Due date: 2025-03-11.

CVE-2024-53704SonicWall SSLVPN: Improper Authentication in Sonicos

Severity
9.8CRITICALNVD
EPSS
93.9%
top 0.13%
CISA KEV
KEVRansomware
Added 2025-02-18
Due 2025-03-11
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 9
KEV addedFeb 18
KEV dueMar 11
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDsonicwall/sonicos7.1.1-70407.1.1-7058+2
CVEListV5sonicwall/sonicos7.1.1-7058 and older versions, 7.1.2-7019, 8.0.0-8035+2

🔴Vulnerability Details

3
GHSA
GHSA-rwgq-wj29-fx3r: An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication2025-01-09
CVEList
CVE-2024-53704: An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication2025-01-09
VulnCheck
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability2024

💥Exploits & PoCs

1
Nuclei
SSL VPN Session Hijacking

🔍Detection Rules

3
Suricata
ET WEB_SPECIFIC_APPS SonicOS SSLVPN Authentication Bypass HTTP Cookie (swap) (CVE-2024-53704)2025-02-13
Suricata
ET WEB_SPECIFIC_APPS SonicOS SSLVPN Authentication Bypass Response (CVE-2024-53704)2025-02-13
Suricata
ET WEB_SPECIFIC_APPS SonicOS SSLVPN Authentication Bypass (CVE-2024-53704)2025-01-30

📋Vendor Advisories

1
CISA
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability2025-02-18

🕵️Threat Intelligence

2
Bleepingcomputer
SonicWall firewall bug leveraged in attacks after PoC exploit release2025-02-14
Bleepingcomputer
SonicWall firewall exploit lets hackers hijack VPN sessions, patch now2025-02-11
CVE-2024-53704 — SonicWall SSLVPN | cvebase