The continued exploitation of SonicWall firewalls shows that installing a firmware update is only one part of remediation. Organizations may remain exposed if stolen credentials, dormant VPN accounts, unsafe LDAP mappings, suspicious sessions, or weak MFA enrolment processes are not addressed.
CVE-2024-40766 is a critical access-control vulnerability affecting certain SonicWall firewalls and SSL VPN services. Although a patch has been available since 2024, ransomware groups such as Akira and Fog have continued gaining access through valid credentials and insecure configurations.
In several incidents, attackers moved from VPN access to internal reconnaissance and ransomware deployment within only a few hours. This leaves organizations with little time to respond after a successful login.
Security teams should review all local firewall and VPN accounts and remove those belonging to former employees, contractors, or unused services. Local accounts must be checked separately from Active Directory because disabling a directory account may not disable its firewall equivalent.
All potentially exposed passwords, VPN credentials, LDAP secrets, API tokens, and certificates should be rotated. Active administrative and VPN sessions should also be terminated, as changing a password may not invalidate an existing attacker session.
LDAP configurations require particular attention. If every authenticated directory user is automatically assigned to a default group with VPN or administrative permissions, a compromised low-privilege account could gain access far beyond its intended role.
MFA enrolment portals should not be openly accessible from the internet. An attacker with a valid password may be able to register their own authenticator and convert stolen credentials into fully authenticated VPN access.
Organizations should monitor successful as well as failed logins. Warning signs include long-running VPN sessions, access from cloud-hosting providers, unexpected countries, stale accounts, and multiple successful logins from the same source.
Management interfaces should be restricted to trusted networks, jump hosts, or approved VPN users. Firewall and VPN logs should be forwarded to an independent logging platform so attackers cannot easily erase evidence.
Older SonicWall Gen 6 devices have reached end of life and should be replaced. Unsupported perimeter equipment creates permanent exposure because new vulnerabilities may never receive fixes.
The key lesson is that patching closes the software vulnerability but does not remove accounts, sessions, credentials, or configuration weaknesses left behind. A device may be fully updated and still provide attackers with several legitimate-looking ways to return.
Effective remediation requires patching, session termination, credential rotation, account cleanup, MFA review, configuration validation, and investigation for prior compromise. Otherwise, the vulnerability may be fixed while the attacker’s access remains perfectly functional.
The vulnerability
Source: CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration., (Tue, Jun 23rd) via SANS Internet Storm Center — published 23 Jun 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.