Sonicwall Flaw VPN could allow computer pirates to kidnap their sessions, so patch now


  • Bishop Fox found a way to abuse a Sonicwall VPN fault
  • It allows threat actors to avoid authentication and kidnapping sessions
  • There are thousands of vulnerable end points

An important vulnerability in the Sonicwall VPN that can be exploited to kidnap sessions and access the target network has now seen its first proof of concept (POC), which means that it is only a matter of time before cybercriminals begin exploit it in nature.

In early January 2025, Sonicwall raised the alarm of vulnerability in Sonica and urged its users to apply the solution immediately. The defect is tracked as CVE-2024-53704, and is described as an inappropriate authentication error in the SSLVPN authentication mechanism. He was given a gravity score of 9.8/10 (critic) and was told that he could abuse a remote attacker to omit authentication.

Leave a Comment

Your email address will not be published. Required fields are marked *