← Global Threat Landscape
CVE-2024-40766
CWE-284
Critical
102.5
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Source: NVD
Signals
- CVSS
- 9.8
- Critical · v3.1
- EPSS
- 18.37%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Sept 2024
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-284
- Published
- 23 Aug 2024
- Last modified 21 Sept 2026
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-40766Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time