LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-53704: SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 18, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 11, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-53704 to its Known Exploited Vulnerabilities catalog on Feb 18, 2025, with a federal patch deadline of Mar 11, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

CVE-2024-53704 is an improper authentication vulnerability in the SSLVPN authentication mechanism of SonicWall SonicOS. It allows a remote attacker to bypass authentication and gain unauthorized access to the SSLVPN service. This matters because SSLVPN often provides remote entry into corporate networks; successful bypass can lead to further compromise, and the vulnerability is known to have been used in ransomware activity.

Defenders should treat exposed SonicWall SSLVPN instances as high priority until they confirm they are not vulnerable and have applied the vendor's recommended actions.

How it works

The flaw is classified as CWE-287 (Improper Authentication). In SonicWall SonicOS, the SSLVPN authentication mechanism fails to correctly enforce authentication checks. A remote attacker can abuse this weakness to bypass the intended authentication process and obtain access without valid credentials.

Exact exploit mechanics are not detailed in the public summary; technical teams should consult the vendor advisory for any additional implementation specifics. The core risk is that an unauthenticated remote party can reach the SSLVPN service and proceed as if authenticated, potentially establishing a tunnel or session into the protected network.

Am I affected? How to find it in your systems

SonicWall SonicOS runs on SonicWall firewall and security appliances that commonly provide perimeter and remote-access functions. SSLVPN is typically enabled on these devices when remote user access is required.

If SSLVPN is internet-facing, prioritize those instances for immediate review.

How to remediate

Apply the vendor update or mitigations named in the SonicWall advisory for CVE-2024-53704 as the primary remediation. CISA directs organizations to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the SSLVPN attack surface.

These steps lower risk but do not replace the vendor fix.

If your data may have been exposed

Actively exploited vulnerabilities of this type, especially those with known ransomware use, frequently lead to network breaches and data exposure. If you determine that an unpatched SonicWall SSLVPN instance was reachable and may have been targeted, treat the incident as a potential compromise: isolate affected systems, preserve logs, and begin forensic review of authentication and post-access activity.

Organizations and individuals can also run a free exposure scan of their email addresses against known breach data to check whether credentials or personal information have already appeared in public breach corpora. Continue monitoring for ransomware indicators and follow your incident-response plan.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SonicOS
WeaknessCWE-287
Added to CISA KEVFeb 18, 2025
Federal patch deadlineMar 11, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities