CRITICAL

CVE-2024-53704

Sonicwall Sonicos 2025-01-09 CVSS v3.1
CVSS
9.8
KEV

Description

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Summary dbcve.org

CVE-2024-53704 is an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication entirely. This critical flaw enables unauthenticated remote attackers to gain access to the VPN infrastructure without valid credentials.

Mitigation

Apply vendor patches immediately as they become available. In the interim, restrict SSLVPN exposure to only necessary networks, implement additional authentication layers such as MFA, and monitor for unusual access patterns or unauthorized sessions.

Weakness (CWE)

CWE-287 Improper Authentication

EPSS Score

95.13%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE