BishopFox: SonicWall CVE-2024-53704: SSL VPN Session Hijacking
See parent toots for the security advisory. BishopFox intends to publish vulnerability CVE-2024-53704 (9.8 critical) SonicOS SSLVPN Authentication Bypass Vulnerability in the next 90 days.
Our current research indicates more than 5,000 affected SonicWall devices remain accessible on the internet. Although significant reverse-engineering effort was required to find and exploit the vulnerability, the exploit itself is rather trivial.
UPDATED 10 February 2025: Bishopfox included full exploitation details in their blog post.
#sonicwall #CVE_2024_53704 #sonicos #sslvpn #vulnerability #CVE #infosec #cybersecurity