{"id":2026,"date":"2025-02-16T10:04:28","date_gmt":"2025-02-16T10:04:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/16\/sonicwall-firewall-authentication-bypass-vulnerability-exploited-in-wild-following-poc-release\/"},"modified":"2025-02-16T10:04:28","modified_gmt":"2025-02-16T10:04:28","slug":"sonicwall-firewall-authentication-bypass-vulnerability-exploited-in-wild-following-poc-release","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/16\/sonicwall-firewall-authentication-bypass-vulnerability-exploited-in-wild-following-poc-release\/","title":{"rendered":"SonicWall Firewall Authentication Bypass Vulnerability Exploited in Wild Following PoC Release"},"content":{"rendered":"<p>    SonicWall Firewall Authentication Bypass Vulnerability Exploited in Wild Following PoC Release<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical authentication bypass vulnerability in SonicWall firewalls, tracked as CVE-2024-53704, is now being actively exploited in the wild, cybersecurity firms warn.<\/p>\n<p>The surge in attacks follows the public release of proof-of-concept (PoC) exploit code on February 10, 2025, by researchers at Bishop Fox, amplifying risks for organizations with unpatched devices.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/unpatched-sonicwall-firewalls-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2024-53704<\/a>, rated 9.3 on the CVSS scale, resides in the SSL VPN authentication mechanism of SonicOS, the operating system powering SonicWall\u2019s Gen 6, Gen 7, and TZ80 firewalls.<\/p>\n<p>Attackers can remotely hijack active VPN sessions by sending a crafted session cookie containing a base64-encoded null byte string to the <code>\/cgi-bin\/sslvpnclient<\/code> endpoint.<\/p>\n<p>Successful exploitation bypasses multi-factor authentication (MFA), exposes private network routes, and allows unauthorized access to internal resources. Compromised sessions also enable threat actors to terminate legitimate user connections.<\/p>\n<p>SonicWall initially disclosed the flaw on January 7, 2025, urging immediate patching. At the time, the vendor reported no evidence of in-the-wild exploitation.<\/p>\n<h2 class=\"wp-block-heading\"><strong>CVE-2024-53704 Exploited in Wild<\/strong><\/h2>\n<p>However, Bishop Fox\u2019s PoC <a href=\"https:\/\/bishopfox.com\/blog\/sonicwall-cve-2024-53704-ssl-vpn-session-hijacking\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">publication<\/a> on February 10 lowered the barrier to entry for attackers. By February 12, Arctic Wolf <a href=\"https:\/\/arcticwolf.com\/resources\/blog\/cve-2024-53704\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">observed<\/a> exploitation attempts originating from fewer than ten distinct IP addresses, primarily hosted on <a href=\"https:\/\/cybersecuritynews.com\/top-10-vps-cloud-web-hosting-providers-a-comprehensive-review\/\" target=\"_blank\" rel=\"noreferrer noopener\">virtual private servers (VPS)<\/a>.<\/p>\n<p>Security analysts attribute the rapid weaponization to the vulnerability\u2019s critical impact and the historical targeting of SonicWall devices by ransomware groups like Akira and Fog.<\/p>\n<p>As of February 7, over 4,500 internet-exposed <a href=\"https:\/\/cybersecuritynews.com\/multiple-sonicwall-vpn-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">SonicWall SSL VPN<\/a> servers remained unpatched, according to Bishop Fox. Affected firmware versions include:<\/p>\n<ul class=\"wp-block-list\">\n<li>SonicOS 7.1.x (up to 7.1.1-7058)<\/li>\n<li>SonicOS 7.1.2-7019<\/li>\n<li>SonicOS 8.0.0-8035<\/li>\n<\/ul>\n<p>Patched versions, such as SonicOS 8.0.0-8037 and 7.1.3-7015, were released in January 2025.<\/p>\n<p>The exploitation pattern mirrors previous campaigns. In late 2024, <a href=\"https:\/\/cybersecuritynews.com\/large-scale-akira-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">Akira<\/a> ransomware affiliates leveraged compromised SonicWall VPN accounts to infiltrate networks, often encrypting data within hours of initial access.<\/p>\n<p>Arctic Wolf warns that CVE-2024-53704 could similarly serve as a gateway for ransomware deployment, credential theft, or espionage.<\/p>\n<p>SonicWall and cybersecurity agencies emphasize urgent action:<\/p>\n<ol class=\"wp-block-list\">\n<li>\n<strong>Upgrade firmware<\/strong> to fixed versions (e.g., 8.0.0-8037 or 7.1.3-7015).<\/li>\n<li>\n<strong>Disable SSL VPN<\/strong> on public interfaces if immediate patching isn\u2019t feasible.<\/li>\n<li>\n<strong>Restrict VPN access<\/strong> to trusted IP ranges and enforce MFA for remaining users.<\/li>\n<\/ol>\n<p>With active exploitation underway, organizations must prioritize patching to mitigate risks. The convergence of public PoC code, high attack feasibility, and SonicWall\u2019s prominence in enterprise networks underscores the urgency. <\/p>\n<p>As Arctic Wolf cautions, delays risk \u201ccatastrophic network compromise\u201d given the severity of the vulnerability and the agility of ransomware actors.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/analysis\/lookup?utm_source=csn_feb&amp;utm_medium=article&amp;utm_campaign=ti&amp;utm_content=lookup-tasks-1&amp;utm_term=120225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/firewall-authentication-bypass-vulnerability\/\">SonicWall Firewall Authentication Bypass Vulnerability Exploited in Wild Following PoC Release<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/firewall-authentication-bypass-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SonicWall Firewall Authentication Bypass Vulnerability Exploited in Wild Following PoC Release A critical authentication bypass vulnerability in SonicWall firewalls, tracked as CVE-2024-53704, is now being actively exploited in the wild, cybersecurity firms warn. The surge in attacks follows the public release of proof-of-concept (PoC) exploit code on February 10, 2025, by researchers at Bishop Fox, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-2026","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2026"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2026"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2026\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}