Vulnerabilities & Exploits

SonicWall Patch Leaves Old Trust State Behind

Patching SonicOS does not clear the part attackers are actually using: carried-forward config and local accounts can keep a firewall open even after the bug is fixed. That makes this a persistence problem, not just a firmware problem, especially for Gen 6 to Gen 7 migrations where old passwords and settings survive the move.

CVE-2024-40766 affects the management interface and SSLVPN on Gen 5, Gen 6, and Gen 7 firewalls. SonicWall’s advisory covers SonicOS 5.9.2.14-12o and older on Gen 5, 6.5.4.14-109n and older on Gen 6, and 7.0.1-5035 and older on Gen 7; the installed base is large, and Gen 6 hardware is now end of life, which keeps exposed devices in circulation.

The practical risk is that a firewall can look current and still be reachable through inherited trust state. That leaves remote access and management paths exposed after the software update, which is why configuration cleanup matters as much as the patch itself.

1 source · Jun 23

CVE-2024-40766

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: an improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially… Known ransomware campaign use. EPSS 18% (97th percentile).

CISA federal remediation date Sep 30 · date passed

Timeline

Sources

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-06-23

Every edition of this story: SonicWall Patch Leaves Old Trust State Behind

More from today