Vulnerabilities & Exploits · Credential Theft

Patched SonicWall VPNs Can Still Bypass MFA

The broken assumption is that a firmware update means the VPN is safe. On SonicWall Gen6 SSL-VPN appliances, that is not true: devices can show as patched and still leave MFA bypassable until the LDAP server is manually reconfigured.

ReliaQuest says it has now seen the first in-the-wild exploitation of CVE-2024-12802 across multiple environments. SonicWall’s advisory says the firmware update alone does not fully mitigate Gen6 devices; Gen7 and Gen8 are not affected in the same way, and the issue matters because attackers used the access for internal recon and credential reuse before moving toward ransomware staging.

The forward risk is a false clean bill of health. Teams that stop at firmware verification may leave a working VPN foothold in place, and that access can be used to test reused credentials and reach internal systems even after the appliance reports as updated.

2 sources · May 20

CVE-2024-12802

NVD KEV

CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40th percentile).

Timeline

Sources

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-05-21

Every edition of this story: Patched SonicWall VPNs Can Still Bypass MFA

More from today