CVE-2024-12802
CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40th percentile).
Vulnerabilities · 117 days ago
The broken assumption is that a firmware update means the VPN is safe. On SonicWall Gen6 SSL-VPN appliances, that is not true: devices can show as patched and still leave MFA bypassable until the LDAP server is manually reconfigured.
ReliaQuest says it has now seen the first in-the-wild exploitation of CVE-2024-12802 across multiple environments. SonicWall’s advisory says the firmware update alone does not fully mitigate Gen6 devices; Gen7 and Gen8 are not affected in the same way, and the issue matters because attackers used the access for internal recon and credential reuse before moving toward ransomware staging.
The forward risk is a false clean bill of health. Teams that stop at firmware verification may leave a working VPN foothold in place, and that access can be used to test reused credentials and reach internal systems even after the appliance reports as updated.
CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40th percentile).
2 sources covering this story
Hackers bypass SonicWall VPN MFA due to incomplete patching
Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks.
Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN
Researchers said a wave of attacks began in February targeting firewalls that appeared to be protected.
Part of the PlainSec briefing for 2026-05-21