Improper Authentication Vulnerability Affects SonicWall SSL-VPN
CVE-2024-22394
9.8CRITICAL
What is CVE-2024-22394?
An improper authentication vulnerability exists within the SSL-VPN feature of SonicWall's SonicOS. When exploited under specific conditions, this vulnerability enables a remote attacker to bypass the authentication mechanism, potentially leading to unauthorized access. This issue is present exclusively in SonicOS firmware version 7.1.1-7040, posing a significant risk to organizations using this version for secure remote access.
Affected Version(s)
SonicOS SonicOS 7.1.1-7040