CISA Added SonicWall SonicOS Authentication Bypass Vulnerability to its Known Exploited Vulnerabilities Catalog (CVE-2024-53704) - #CVE-2024-53704
A critical authentication bypass vulnerability (CVE-2024-53704) in SonicWall firewalls running specific versions of SonicOS has been discovered and exploited. This high-severity flaw, affecting nearly 4,500 internet-exposed firewalls, allows attackers to hijack VPN sessions, bypass multi-factor authentication, and gain unauthorized access to internal resources. SonicWall released patches in early January 2025, but following the public disclosure of a proof-of-concept exploit by Bishop Fox, active exploitation attempts have been observed. The vulnerability, with a CVSS score of 9.8, poses significant risks including potential ransomware deployment and data breaches. Cybersecurity firms like Arctic Wolf have reported ongoing attacks, emphasizing the urgent need for organizations to apply the available patches or implement recommended mitigations such as restricting SSL VPN access to trusted sources.