Vulnerabilities · 117 days ago

Patched SonicWall VPNs Can Still Bypass MFA

The broken assumption is that a firmware update means the VPN is safe. On SonicWall Gen6 SSL-VPN appliances, that is not true: devices can show as patched and still leave MFA bypassable until the LDAP server is manually reconfigured.

ReliaQuest says it has now seen the first in-the-wild exploitation of CVE-2024-12802 across multiple environments. SonicWall’s advisory says the firmware update alone does not fully mitigate Gen6 devices; Gen7 and Gen8 are not affected in the same way, and the issue matters because attackers used the access for internal recon and credential reuse before moving toward ransomware staging.

The forward risk is a false clean bill of health. Teams that stop at firmware verification may leave a working VPN foothold in place, and that access can be used to test reused credentials and reach internal systems even after the appliance reports as updated.

CVE-2024-12802

NVD KEV

CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40th percentile).

Timeline

Sources

2 sources covering this story

Entities

Vendor digest: SonicWall

Part of the PlainSec briefing for 2026-05-21

Editions

Related stories