The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Contact your IT/security provider now and ask for an immediate firmware upgrade for SonicWall SonicOS to a fixed version that removes CVE-2024-40766 exposure (for Gen 5/6 and Gen 7 before/at 7.0.1-5035). 2) If you can’t upgrade right away, restrict/disable public access to SonicOS management from the internet and limit access to trusted admin IPs only. 3) Check whether your SonicWall models and SonicOS versions fall into the affected ranges and prioritize any matching devices first.
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
In plain language
Written by AI from the record
CVE-2024-40766 is a critical SonicWall firewall management security flaw that is already being exploited in the wild; if you run SonicWall SonicOS firewall management (especially Gen 5/6 or Gen 7 on SonicOS 7.0.1-5035 or older), you should act immediately.
What is it
This vulnerability is like leaving a door to your building’s office unlocked but with a “partial” lock—wrong people may be able to get access to internal systems they shouldn’t. Depending on how it’s used, it can also cause the firewall to crash, disrupting your network. Because it targets the firewall’s management access, it’s particularly serious.
Who is affected
This matters to you if you use or operate SonicWall firewall devices running SonicOS management. It affects SonicWall Firewall Gen 5 and Gen 6 devices, and SonicWall Gen 7 devices running SonicOS 7.0.1-5035 and older versions. If your business relies on these firewalls to secure your network, treat this as urgent.
How urgent is it
This is a RED situation because attackers are already exploiting it in the real world (it is listed in CISA KEV and press reports indicate it is being used in the wild). With ransomware-linked exploitation reported and a high estimated likelihood of exploitation in the next 30 days, you should not wait for the next routine maintenance window. Move to remediation immediately.
What to do — in detail
Identify exposure: Confirm your SonicWall model (Gen 5/Gen 6, or Gen 7) and your SonicOS version. This issue affects Gen 5/6 devices, and Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Patch immediately: Upgrade SonicOS to a version that addresses the improper access control in SonicOS management access. Apply updates as soon as possible to all affected devices (prioritize those directly connected to the internet and those used for remote administration).
Lock down management access: While patching, reduce the chance of misuse by ensuring SonicOS management is not reachable from untrusted networks. Practically, this means restricting management interfaces to trusted IP addresses or a private administration network, and ensuring internet-facing admin access is disabled.
Validate after changes: After upgrading and tightening access, verify that management functions still work for authorized users and that the management interface is not accessible from untrusted sources.
Monitor for signs of compromise: Because exploitation is known to be happening in the wild, watch for unusual management logins, unexpected configuration changes, unexpected reboots/crashes (this flaw can cause crashes in specific conditions), and any signs of malware/ransomware activity on connected systems. Escalate quickly if you see suspicious admin activity.
Review access practices: Confirm that admin accounts are limited to the fewest necessary users, and that credentials are not shared. If your environment supports it, ensure stronger authentication and careful account management are in place for firewall administration.
Technical context
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS management access. Affected systems include SonicWall Firewall Gen 5 and Gen 6 devices, plus SonicWall Gen 7 devices running SonicOS 7.0.1-5035 and older versions. The impact includes unauthorized resource access, and in specific conditions the device can crash.
Exploitation and risk: The issue is listed by CISA as a Known Exploited Vulnerability (CISA KEV) and press reports indicate it is being exploited in the wild (it was resurfacing with the named actor Akira). The public exploit availability is reported as no, and there is no Nuclei detection template mentioned.
About EPSS/KEV: EPSS (15.7% estimated probability in the next 30 days, per the provided data) is a statistical estimate of how likely it is that attackers will exploit the CVE soon; KEV means the vulnerability is already known to be actively exploited and added to CISA’s urgent list, which is why this is treated as high priority.
Attack vector (from the provided context): The weakness targets management access on SonicWall SonicOS, meaning an attacker would attempt to reach or interact with the firewall’s management functions in a way that bypasses intended access controls.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.