Rewterz
Lazarus aka Hidden Cobra APT Group – Active IOCs
July 22, 2024
Rewterz
VMware ESXi Systems Targeted by New Play Ransomware Linux Variant – Active IOCs
July 22, 2024

Multiple SonicWall Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-40764 CVSS:7.5

SonicWall SonicOS is vulnerable to a denial of service, caused by a heap-based buffer overflow in the IPSec VPN. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.

CVE-2024-29014 CVSS:7.1

SonicWall NetExtender Windows client could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an error when processing an EPC Client update. By using a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Denial of Service
  • Code Execution

Indicators of Compromise

CVE

  • CVE-2024-40764
  • CVE-2024-29014

Affected Vendors

Sonicwall

Affected Products

  • SonicWall SonicOS 6.5.4.4-44v-21-2395
  • SonicWall NetExtender Windows 10.2.339

Remediation

Refer to SonicWall Advisory or patch, upgrade or suggested workaround information.

CVE-2024-40764

CVE-2024-29014