Skip to main content
CloudKey

1 actively exploited

SonicWall 7.1.1-7040: known CVEs & fixed releases

16 CVEs affect this build · 1 in CISA KEV (actively exploited) · highest CVSS 9.8 · 6 builds behind the latest 7.1.2-7019 · updated 2026-06-26

Patch path: upgrade to 6.5.4.v-21s-rc2457 or 6.5.5.2-28n or 7.0.1-5161 or 7.1.1-7058 or 7.1.2-7019 or 7.3.0-7012 or 7.3.1-7013 or 7.3.2-7010 or 8.0.3-8011 or 8.2.0-8009 to clear the exploited issues below.

  • KEV · exploited CRITICAL
    CVE-2024-53704

    SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

    SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.

    CVSS
    9.8
    EPSS
    95%
    KEV added
    2025-02-18
    Published
    2025-01-09
  • CRITICAL
    CVE-2024-3596

    CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability

    RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

    CVSS
    9
    EPSS
    15%
    Published
    2024-07-09
  • CRITICAL
    CVE-2024-22394

    CVE-2024-22394

    An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.

    CVSS
    9.8
    Published
    2024-02-08
  • CRITICAL
    CVE-2025-40600

    CVE-2025-40600

    Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

    CVSS
    9.8
    Published
    2025-07-29
  • CVE-2026-0204

    A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

    CVSS
    8
    Published
    2026-04-29
    Fixed in 6.5.5.2-28n, 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗
  • CVE-2025-40601

    A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.

    CVSS
    7.5
    Published
    2025-11-20
    Fixed in 7.3.1-7013, 8.0.3-8011 NVD ↗psirt.global.sonicwall.com ↗
  • CVE-2024-40764

    Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

    CVSS
    7.5
    Published
    2024-07-18
    Fixed in 6.5.4.v-21s-rc2457, 7.0.1-5161, 7.1.1-7058 NVD ↗psirt.global.sonicwall.com ↗
  • CVE-2024-29012

    Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.

    CVSS
    7.5
    Published
    2024-06-20
    Fixed in 7.0.1-5161, 7.1.1-7058, 7.1.2-7019 NVD ↗psirt.global.sonicwall.com ↗
  • MEDIUM
    CVE-2026-0205

    CVE-2026-0205

    A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

    CVSS
    6.8
    Published
    2026-04-29
    Fixed in 6.5.5.2-28n, 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗
  • CVE-2024-29013

    Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial of Service (DoS) via memcpy function.

    CVSS
    6.5
    Published
    2024-06-20
    Fixed in 7.0.1-5161, 7.1.1-7058, 7.1.2-7019 NVD ↗psirt.global.sonicwall.com ↗
  • MEDIUM
    CVE-2026-0206

    CVE-2026-0206

    A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.

    CVSS
    4.9
    Published
    2026-04-29
    Fixed in 6.5.5.2-28n, 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗
  • MEDIUM
    CVE-2026-3439

    CVE-2026-3439

    A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.

    CVSS
    4.9
    Published
    2026-03-04
    Fixed in 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗
  • MEDIUM
    CVE-2026-0399

    CVE-2026-0399

    Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.

    CVSS
    4.9
    Published
    2026-02-24
    Fixed in 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗
  • MEDIUM
    CVE-2026-0400

    CVE-2026-0400

    A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.

    CVSS
    4.9
    Published
    2026-02-24
    Fixed in 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗
  • MEDIUM
    CVE-2026-0402

    CVE-2026-0402

    A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.

    CVSS
    4.9
    Published
    2026-02-24
    Fixed in 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗
  • MEDIUM
    CVE-2026-0401

    CVE-2026-0401

    A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.

    CVSS
    4.9
    Published
    2026-02-24
    Fixed in 7.3.2-7010, 8.2.0-8009 NVD ↗psirt.global.sonicwall.com ↗

Stop checking versions by hand

Is your whole fleet exposed, not just this SonicWall?

VulnMonitor reconciles every advisory against your real inventory and ranks what matters by actual exploitation (CISA KEV, EPSS), not raw CVSS. New CVE hits your gear, it is on your queue with the fix attached.

Free to start · no credit card