Skip to content

Commit

Permalink
Update DIVD-2025-00002.md
Browse files Browse the repository at this point in the history
Aanpassingen na advies van Thijs
  • Loading branch information
sT0wn-nl authored Jan 10, 2025
1 parent 38cbd51 commit 8944f6b
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions _cases/2025/DIVD-2025-00002.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ researchers:
- Thijs Alkemade (Computest)
cves:
- CVE-2024-53704
- CVE-2024-40762
product:
- SonicWall SonicOS
versions:
Expand Down Expand Up @@ -36,19 +37,18 @@ timeline:
---

## Summary
SonicWall has identified an Improper Authentication vulnerability in the SSLVPN authentication mechanism. A successful exploit of this vulnerability could allow an attacker to gain unauthorized access, with potential impacts to the confidentiality, integrity, and availability of the networks that were supposed to be protected by the VPN.
On 7 January 2025, SonicWall released patches for multiple vulnerabilities in Gen6 and Gen7 firewalls. The patched vulnerabilities include two vulnerabilities in the SSLVPN functionality that made it possible to take over established SSLVPN sessions, thereby gaining access to the internal network (CVE-2024-53704 and CVE-2024-40762). While SonicWall has not yet observed that these vulnerabilities are being exploited in the wild, they do describe them as at imminent risk of exploitation.

## Recommendations

To remediate {% cve CVE-2024-53704 %}, apply the patch as soon as possible for impacted products, latest patch builds are available for download on [mysonicwall.com](https://mysonicwall.com).

## What we are doing

DIVD is currently working to identify parties that are running a vulnerable version of SonicWall SSL-VPN service and to notify these parties.

{% include timeline.html %}

## More information

* {% cve CVE-2024-53704 %}
* {% cve CVE-2024-40762 %}
* [SonicWall Security Bulletin](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003)

0 comments on commit 8944f6b

Please sign in to comment.