CISA KEV · catalog date Sep 9, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2024-40766
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific…
Exploited in the wild (CISA KEV since Sep 9, 2024). NVD reports CVSS 3.1 9.8. EPSS estimates 18.2% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
- State
- PUBLISHED
- Published
- Aug 23, 2024
- Updated
- Oct 21, 2025
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAsonicwallOriginal evidence ↗
Record text: An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Inspect raw assertion
- Field
container- Value
- An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: SonicWall SonicOS Improper Access Control Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall SonicOS Improper Access Control Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 18.18% probability · 96.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.181770000000; percentile 0.969850000000
FIRST EPSS · score date Aug 27, 2026 · 97th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
Inspect raw assertion
- Field
container- Value
- An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.
SonicWall SonicOS Improper Access Control Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall SonicOS Improper Access Control Vulnerability
18.18% probability · 96.99th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.181770000000; percentile 0.969850000000
Applicability
Cited product scope
Grouped from 8 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
56 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "5.9.2.14-12o"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.5.4.14-109n"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "7.0.1-5035"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "5.9.2.14-12o"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.5.4.14-109n"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "7.0.1-5035"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "5.9.2.14-12o"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "6.5.4.14-109n"}, {"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "7.0.1-5035"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "5.9.2.14-12o and older versions"}, {"status": "affected", "version": "6.5.4.14-109n and older versions"}, {"status": "affected", "version": "7.0.1-5035 and older versions"}]product-4a4490d085d351800978492e1641938b1887bec09d449679baf6f93c3367d459Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_2650:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b7bcdfee-dc5a-44b8-85df-8bfc02b1a973
product-673117bd8776e02e74068c74394f87a86cc3e426fb4bb297b07a7a02abbfd557Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d8b0c7a-fd65-47ca-a625-150a90efa7a1
product-3230998634024586283eb7d11ac2f057b5db22e7dbf9326a1b3460865554b518Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_3600:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8a24bcc0-ce41-49af-b03d-d4fcb422503b
product-ad98a4f1fe97cede663efd8ce03b52464501862d0e2bdce2a830a3b01b482609Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_3650:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
043858a6-26ac-4eb0-a240-a43ad08c6ad5
product-5a3fa65e2a189c8facfc0c4f6473b5806e2d32806948bf49b33caf920338b257Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a69e000b-5806-46fd-a233-4e2cc9dd38d2
product-b68289d3d143c238bb78db4eb2176ba62cd85484d7353bda0e9b0269bcce45a0Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_4600:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8fd73880-dc60-467f-99b6-69807d58a840
product-e9e70d99c176c0321c4ab98b145c6b3cfc7c25bfa664900ddb4bb439e9158f60Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_4650:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
73bb9452-a014-4a68-9662-63e6c60eead2
product-239c8e8ef47d51bb08cb8337dddb1caf08aafe251e81b532c5f9761b09bf4c1aLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8df4a322-7cc7-4ab9-b10e-fff34df2182d
product-28b70aa42bf4a7d1c6a8d597e05dffbe3258e5827a63150db519bb2a79b5bc63Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_5600:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b0cf683a-7e83-464b-8a0d-4cc641377fa6
product-9992e8f21d25970c7fd3c8f08e80000a0e6a30a6318673b39f11b71ccbbac9edLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_5650:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9faaebb4-f180-4195-ba7f-591ab02eedc9
product-dee1d892c41f618914799c2e8782f436cdb306f8b5b02803ca8e50ffbe420ebdLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c15fed5-c48c-47cf-9645-0563d77883c1
product-6c5b597ca80a6e912faad3c3dfe1771e1b61ed032a2247a6db9bb320744011f2Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_6600:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd9c3f77-2f1a-4c4f-a8f8-cdbfb7b87891
product-6e9e007accb084d0a4aa8398052b7362e61862b1a5880fda5f797b0ed4f92ed9Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_6650:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
676b05b2-716e-4dc4-bee8-0e3bcca5db27
product-5888cbc14bd3d33584c779cd787b2cf3af831c2018711369f070f86181980e10Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a884b1bb-f201-4c77-9f6e-b8a884dcd4c2
product-583608ad2eed376bf7f5d8e7f14a16d915747e91e3d430e485b95fbb508409e5Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7c3ba5a3-1160-4793-a8d6-40b9d264bcc4
product-60cff82ad64a904b621b4400d6cb5153d34299272fea11f4df46fac46ab61b5cLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6739dea3-06ff-4feb-9931-0db27f63b70e
product-1cf9117f99a140d95a2500b3cf07d28275b6e7225fc5e75555ac46421052a6efLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_12400:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f2f22ab1-044c-45f1-bd33-82bb46402363
product-0aecb111f927d1be92eaf151ec9ec1d802d83c690397569beb42dc8c8f8bdaeeLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_12800:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e62ead79-2cd4-4479-b26a-a0c97b5b241a
product-5effcb3c3c55f05592e2f2712cda9b00156edc998efaea8731637b4db7f430d8Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0250edf9-0aef-4711-8ef6-d447cf48bcaf
product-d5708d3a753f4cbdd562befe454e107df6a6e03466c723c3c9661cc71d3fa30dLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:sm_9200:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fef2b435-957c-4bbe-937d-23e4f33189ef
product-1e3fcd420401b7c1d533ace528fecbc08a17a707d9a903b28f42e34cb24a6da2Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:sm_9250:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0ce4fe75-10ad-47d4-af87-e4c294f89ea8
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-85898d6fe491d9f6f381bbdf2d6cef63a8d780eebbf13fe9fb76aeb30af6b3d7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cdca6069-9d3f-463a-9b52-087149ca4b47e5790dc7-1a58-4519-ba65-4806911dd167e7017013-97eb-4433-a686-ceac549f97f1fd63f223-ff29-443f-8c61-fc2294e67fa5Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
02acc19a-0e6a-481e-8fad-d6400f0686424e184d56-ffd4-4391-a57e-7ecf9d1efe7179a407e9-69ca-4e06-beea-2f1f6ace508be156133b-715e-4d24-9f33-4a38c94c4c5aAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:LCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:LDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L- Validation
- Valid match
- Recomputed
- 9.3
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.