Alert: SonicWall CVE-2024-40766 Exploit via SSL VPN

The Blackpoint Adversary Pursuit Group (APG) and the Blackpoint Active SOC have just triangulated published news of active exploitation of a SonicWall SSL VPN vulnerability being used by threat actors to gain initial access.

Our SOC recently responded to SSL VPN initial-access attempts inside Blackpoint-managed environments, and a full analysis of that incident is forthcoming next Tuesday, September 10.

Based on the available information, we consider this alert on SonicWall CVE-2024-40766 critically important for organizations running affected devices.

What Is CVE-2024-40766?

CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS. The vulnerability affects certain SonicWall firewall and SSL VPN configurations and can allow unauthorized access to protected resources.

With a CVSS score of 9.3, the vulnerability was classified as critical. Its potential to provide unauthorized access through an internet-facing security appliance made it particularly significant for organizations running affected SonicWall devices.

What We Know About SonicWall CVE-2024-40766

Per SonicWall’s security bulletin, the key facts for defenders are:

  • Severity: Critical — CVSS score of 9.3.
  • Vulnerability type: Improper Access Control (IAC).
  • How it’s exploited: Threat actors can exploit the vulnerability to gain initial access via SSL VPN, then move into sensitive environments and deploy malicious payloads.
  • Affected devices: SonicWall Gen 5 and Gen 6 devices, plus Gen 7 devices running SonicOS 7.0.1-5035 and older.
  • What it means for MSPs: The APG assesses that there is an even chance that threat actors could abuse this access to conduct supply-chain attacks against downstream customers.

Why SonicWall SSL VPNs Are a Target

SSL VPN infrastructure is frequently targeted because it provides remote access to internal environments. When a vulnerability affects an internet-facing VPN product, threat actors may be able to exploit the device itself rather than first compromising an endpoint inside the network.

From an attacker’s perspective, compromised VPN access can provide:

  • A potential entry point into an internal network
  • Access to resources protected by the VPN
  • An opportunity to conduct additional activity after gaining access

Since SSL VPN services are designed to be reachable from the internet, they can also be exposed to automated scanning and targeted exploitation when new vulnerabilities are disclosed.

Potential Risk for Your Organization

If successfully exploited, an affected SonicWall device can give an attacker an entry point into the network behind it, potentially exposing sensitive systems, credentials, and data.

The APG and the Blackpoint SOC both assess a high likelihood of attempted exploitation in environments running affected versions of SonicOS. According to SonicWall’s own advisory, threat actors have already attempted to exploit CVE-2024-40766 for initial access in the wild.

The Blackpoint Active SOC also responds to incidents involving SSL VPN abuse for initial access, including a recent incident on September 1, 2024, involving an Institutions & Organizations partner. Public analysis of that incident will be available next week, on Tuesday, September 10.

What Can Happen After Initial Access?

Gaining initial access doesn’t mean an attacker immediately deploys malware or disrupts an environment. More often, it’s an opportunity to conduct further reconnaissance and expand access.

After gaining a foothold, threat actors may attempt to:

  • Identify additional systems and accounts
  • Obtain or abuse credentials
  • Move laterally across the environment
  • Establish persistence
  • Deploy additional tools or payloads
  • Access sensitive data or systems

What follows depends on the attacker’s objectives and the access available to them. This is why securing VPN and firewall infrastructure should be part of a broader effort to prevent and detect intrusions.

How to Mitigate Exploitation Risk of SonicWall CVE-2024-40766

Per SonicWall’s advisory, organizations can take the following steps to reduce the risk of exploitation:

  • Apply the patch as soon as possible for affected products, using the latest available patch builds available through MySonicWall.
  • Enforce multi-factor authentication (MFA) on all VPN accounts.
  • Consider regenerating the VPN SSL certificate.
  • Restrict firewall management to trusted sources.
  • Disable firewall WAN management from internet access wherever possible.

For Gen 5 and Gen 6 Devices

  • SSLVPN users with local accounts should update their passwords immediately.
  • Administrators should enable the “User must change password” option for local users.

What to Monitor After a SonicWall SSL VPN Vulnerability

Organizations responding to a vulnerability affecting an internet-facing VPN or firewall should review activity around the affected device. Looking for unusual activity can help security teams determine whether further investigation is warranted.

Depending on the environment, this may include reviewing:

  • Unexpected SSL VPN authentication activity
  • Unusual administrator activity
  • Changes to VPN accounts or access settings
  • Authentication attempts from unfamiliar locations or IP addresses
  • Suspicious activity following VPN authentication
  • Signs of credential abuse or lateral movement

These signals are not, by themselves, confirmation that CVE-2024-40766 was exploited. Reviewed alongside other security telemetry, they can help point security teams toward activity that deserves a closer look.

See how Blackpoint’s Managed Detection & Response helps MSPs monitor for suspicious activity across client environments.

SOC Status for SonicWall CVE-2024-40766 Exploitation

While the Blackpoint Active SOC team has recently combatted SSLVPN initial access compromise within our managed environments, we have NOT confirmed explicit indicators of compromise (IoCs) in our partners’ environments showing threat actor exploitation of SonicWall CVE-2024-40766, including for your organization.

The Active SOC team will continue to actively monitor for any IoCs associated with this incident. The APG team will update this notice as a courtesy, should we detect otherwise.

Want to strengthen threat detection and response across your client environments? Contact our team to get started.

Resources and References

  1. SonicWall Advisory: SonicOS Improper Access Control Vulnerability (SNWLID-2024-0015)
  2. MySonicWall (patch downloads)
DATE PUBLISHEDSeptember 6, 2024
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY