SonicWall Firewalls Now Under Attack: Patch ASAP Or Risk Intrusion Via Your SSL VPN

Miscreants are actively abusing a high-severity authentication bypass bug in unpatched internet-facing SonicWall firewalls following the public release of proof-of-concept exploit code.
The vulnerability, tracked as CVE-2024-53704, is a flaw in the SSL VPN authentication mechanism in SonicOS, the operating system that SonicWall firewalls use. If exploited, it allows remote attackers to bypass authentication on vulnerable SonicOS equipment, hijack the devices' active SSL VPN sessions, and gain unauthorized access to affected networks.
"Shortly after the proof-of-concept was made public, Arctic Wolf began observing exploitation attempts of this vulnerability in the threat landscape," the threat monitoring and detection outfit warned Thursday.
SonicWall first disclosed CVE-2024-53704 in early January. The security hole affects multiple Gen 7 and TZ80 SonicWall firewalls. The good news is upgrading to the latest version of SonicOS will plug the hole.
Given that attackers ranging from suspected Chinese spies to ransomware criminals have a history of exploiting buggy SonicWall devices, you'd hope users patched this hole immediately.
Not everyone got the memo, it appears.
- SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix
- Akira ransomware is encrypting victims again following pure extortion fling
- More than 178,000 SonicWall firewalls are exposed to old denial of service bugs
- Suspected Chinese cyber spies target unpatched SonicWall devices
On January 30, Bishop Fox researchers said they were able exploit the flaw in unpatched firewalls and called the attack "trivial."
SonicWall echoed this call to action in an updated security advisory, and said "customers must immediately update." If for whatever reason you can't update to a fixed firmware version, SonicWall suggests disabling the SSL VPN mechanism.
More specifically on the outcome of exploitation, Bishop Fox noted:
Later, on February 10, Bishop Fox published full exploit details, including code, providing step-by-step instructions for how to bypass authentication and hijack active SSL VPN sessions. The researchers also noted that, as of February 7, about 4,500 internet-facing SonicWall SSL VPN servers remain unpatched.
"If you have not yet upgraded your SonicWall firewalls to the latest available firmware, please follow SonicWall's advice and upgrade immediately," Bishop Fox senior security engineer Jon Williams urged.
We couldn't agree more. Arctic Wolf also told us today: "We see evidence of CVE-2024-53704 exploitation attempts since February 12, 2025, with fewer than ten distinct sources. The traffic originates from a handful of VPS hosting providers, and the activity includes scanning for a variety of other vulnerabilities as well." ®
From Chip War To Cloud War: The Next Frontier In Global Tech Competition
The global chip war, characterized by intense competition among nations and corporations for supremacy in semiconductor ... Read more
The High Stakes Of Tech Regulation: Security Risks And Market Dynamics
The influence of tech giants in the global economy continues to grow, raising crucial questions about how to balance sec... Read more
The Tyranny Of Instagram Interiors: Why It's Time To Break Free From Algorithm-Driven Aesthetics
Instagram has become a dominant force in shaping interior design trends, offering a seemingly endless stream of inspirat... Read more
The Data Crunch In AI: Strategies For Sustainability
Exploring solutions to the imminent exhaustion of internet data for AI training.As the artificial intelligence (AI) indu... Read more
Google Abandons Four-Year Effort To Remove Cookies From Chrome Browser
After four years of dedicated effort, Google has decided to abandon its plan to remove third-party cookies from its Chro... Read more
LinkedIn Embraces AI And Gamification To Drive User Engagement And Revenue
In an effort to tackle slowing revenue growth and enhance user engagement, LinkedIn is turning to artificial intelligenc... Read more