---
id: CVE-2024-40766
title: >-
  An improper access control vulnerability has been identified in the SonicWall
  SonicOS management access, potentially leading to unauthorized resource access
  and in specific conditions, causing the firewall to crash
summary: >-
  An improper access control vulnerability has been identified in the SonicWall
  SonicOS management access, potentially leading to unauthorized resource access
  and in specific conditions, causing the firewall to crash. This issue affects
  So…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: sonicwall
product: sonicos
affected:
  - sonicos < 5.9.2.14-13o
  - sonicos < 6.5.2.8-2n
  - sonicos < 6.5.4.15.116n
  - sonicos <= 7.0.1-5035
patched:
  - sonicos 6.5.4.15.116n
published: '2024-08-23'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T21:17:02.403'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-40766'
references:
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015'
    label: PSIRT@sonicwall.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-40766
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - cve.org
  - exploit-available
epss: 0.18379
epssPercentile: 0.9713
kev: true
kevDateAdded: '2024-09-09'
kevDueDate: '2024-09-30'
kevRansomware: true
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2024-09-09T14:11:51.602153Z'
scores:
  nvd: 9.8
  adp: 9.3
ingestedAt: '2026-09-21T20:52:58.300Z'
---

## Overview

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

## Affected

- `sonicos < 5.9.2.14-13o`
- `sonicos < 6.5.2.8-2n`
- `sonicos < 6.5.4.15.116n`
- `sonicos <= 7.0.1-5035`

## Remediation

Upgrade past the affected range:

- `sonicos 6.5.4.15.116n`
