Unauthenticated DoS Vulnerability in SonicOS IPSec VPN
CVE-2024-40764

7.5HIGH

Key Information:

Vendor
Sonicwall
Status
Vendor
CVE Published:
18 July 2024

Summary

A heap-based buffer overflow vulnerability has been identified in the SonicOS IPSec VPN, which can be exploited by unauthenticated remote attackers. The exploitation of this vulnerability could lead to a Denial of Service (DoS), affecting the availability of the service. It is critical for users of this platform to apply the recommended security patches and updates as provided by SonicWall to protect against potential threats. For further details on mitigation strategies, refer to the vendor advisory.

Affected Version(s)

SonicOS Gen6 6.5.4.4-44v-21-2395 and older versions

SonicOS Gen6 7.0.1-5151 and older versions

SonicOS Gen6 7.1.1-7051 and older versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.