Evidence dossier

CVE-2024-53704

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Exploited in the wild (CISA KEV since Feb 18, 2025). NVD reports CVSS 3.1 9.8. Severity assessments differ within at least one CVSS version. EPSS estimates 95.1% exploit likelihood as of Jul 31, 2026.

80.090.1Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

State
PUBLISHED
Published
Jan 9, 2025
Updated
Aug 4, 2026
Evidence coverage
72%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
    Original evidence ↗
  2. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 95.13% probability · 99.86th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.951320000000; percentile 0.998560000000
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    sonicwall

    Record text: An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

    Inspect raw assertion
    Field
    container
    Value
    An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
    Original evidence ↗

Assessments differ

NVD9.8CVSS 3.1 · source date omitted
CVE Program source8.2CVSS 3.1 · source date omitted

Values are shown separately by source and CVSS version.

ExploitationCatalog member

CISA KEV · catalog date Feb 18, 2025 · first observed Jul 19, 2026

Exploit likelihood95.13%

FIRST EPSS · score date Jul 31, 2026 · 99.9th percentile · first observed Aug 1, 2026

SeverityAssessments differ

NVD · CVSS 3.1 · first observed Aug 4, 2026 · values shown separately below

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentAssessments differ

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
Resolve conflict
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA KEVOriginal assertion
Exploitation cataloged

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

95.13% probability · 99.86th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.951320000000; percentile 0.998560000000
Source dateFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
sonicwallOriginal assertion
Record text

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Inspect raw assertion
Field
container
Value
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
26Underlying assertions
24Canonical products
3Target assertions
23Constraint assertions

Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

25 scope groups

sonicwall · source assertedSonicWallSonicOSDirect source scope
Affected: 7.1.1-7058 and older versionsAffected: 7.1.2-7019Affected: 8.0.0-8035
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "7.1.1-7058 and older versions"}, {"status": "affected", "version": "7.1.2-7019"}, {"status": "affected", "version": "8.0.0-8035"}]
NVD CPE · HARDWAREsonicwallnsa_2700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-673117bd8776e02e74068c74394f87a86cc3e426fb4bb297b07a7a02abbfd557Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d8b0c7a-fd65-47ca-a625-150a90efa7a1
NVD CPE · HARDWAREsonicwallnsa_3700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5a3fa65e2a189c8facfc0c4f6473b5806e2d32806948bf49b33caf920338b257Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a69e000b-5806-46fd-a233-4e2cc9dd38d2
NVD CPE · HARDWAREsonicwallnsa_4700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-239c8e8ef47d51bb08cb8337dddb1caf08aafe251e81b532c5f9761b09bf4c1aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8df4a322-7cc7-4ab9-b10e-fff34df2182d
NVD CPE · HARDWAREsonicwallnsa_5700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-dee1d892c41f618914799c2e8782f436cdb306f8b5b02803ca8e50ffbe420ebdLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4c15fed5-c48c-47cf-9645-0563d77883c1
NVD CPE · HARDWAREsonicwallnsa_6700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5888cbc14bd3d33584c779cd787b2cf3af831c2018711369f070f86181980e10Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a884b1bb-f201-4c77-9f6e-b8a884dcd4c2
NVD CPE · HARDWAREsonicwallnssp_10700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-583608ad2eed376bf7f5d8e7f14a16d915747e91e3d430e485b95fbb508409e5Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c3ba5a3-1160-4793-a8d6-40b9d264bcc4
NVD CPE · HARDWAREsonicwallnssp_11700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-60cff82ad64a904b621b4400d6cb5153d34299272fea11f4df46fac46ab61b5cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6739dea3-06ff-4feb-9931-0db27f63b70e
NVD CPE · HARDWAREsonicwallnssp_13700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-5effcb3c3c55f05592e2f2712cda9b00156edc998efaea8731637b4db7f430d8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0250edf9-0aef-4711-8ef6-d447cf48bcaf
NVD CPE · HARDWAREsonicwallnssp_15700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-e41f245c444aeb7286921d443f470a96a7c13aabab9a84c9cc0496aaa626b00eLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nssp_15700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7d6cf3cf-256c-4c04-8bdf-b16398cd0459
NVD CPE · HARDWAREsonicwallnsv_270Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8292184067857470da2371294fe91de9b412835f57b2c064f1a009249e575645Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsv_270:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f2abc8d8-2943-4073-9568-e87961a18998
NVD CPE · HARDWAREsonicwallnsv_470Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d16a47ccd8acb9353db836069888ae8cbd064435942e5beadee83bae51f3d31fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsv_470:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f57d527-aa3f-45e9-9bce-6f76691066b5
NVD CPE · HARDWAREsonicwallnsv_870Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d628a0dc74e75cd37ba092a3f0406b87c1c27389b08d54c3c40add950dab2021Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:nsv_870:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f5ecccf0-a5d8-42a8-8ec1-d12b49b1124a
NVD CPE · OPERATING SYSTEMsonicwallsonicosVulnerable target · 3 assertions
Any version (unconstrained) (>= 7.1.1-7040, <= 7.1.1-7058); Version 7.1.2-7019; Version 8.0.0-8035Canonical identity product-85898d6fe491d9f6f381bbdf2d6cef63a8d780eebbf13fe9fb76aeb30af6b3d7Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:sonicwall:sonicos:7.1.2-7019:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0131b5d1-47ff-4a35-8983-7c08e021f7a4
  2. cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 7.1.1-7040; through including 7.1.1-7058
    Match ID
    065dd610-7821-4a0e-9cc8-1255f1729126
  3. cpe:2.3:o:sonicwall:sonicos:8.0.0-8035:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    495254b3-5733-467e-aaa0-a9d385328c8e
NVD CPE · HARDWAREsonicwalltz270Environmental constraint · 1 assertions
Version not applicableCanonical identity product-23a7b086ae83d780a3f91a4ce4cbf4ea1844edbc00b631cc1e2666ffff08385dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz270:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    70340dd4-687b-402c-85af-c2b80d0f1600
NVD CPE · HARDWAREsonicwalltz270wEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-3a897e8969dc90bf02e979f957d908e561ecd1cac3feb21ff8489f7166e6b069Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz270w:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    52847ba2-470b-4078-a79b-52095db9214b
NVD CPE · HARDWAREsonicwalltz370Environmental constraint · 1 assertions
Version not applicableCanonical identity product-3c9a8e100503fe45fe731c0bde2acceb764b7bfb554755d6c18dc3cbcfe91b07Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz370:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9853ae3a-b0ea-4249-aa7d-1f2051c9bf91
NVD CPE · HARDWAREsonicwalltz370wEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-857f02f449eef288d4709b6a06edc69b9b916c372d90424fbe3657fc17341161Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz370w:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4dbdd10c-f89d-4051-bc70-67b41167ff9b
NVD CPE · HARDWAREsonicwalltz470Environmental constraint · 1 assertions
Version not applicableCanonical identity product-0362aebe42896e7a4ab46a8b15f961c6853cc46c0b5f5a9d320e0ddeb7b9fa52Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz470:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6c23940e-2f9d-447b-a740-42035ed5d400
NVD CPE · HARDWAREsonicwalltz470wEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-458561e75a93fac8630fff75ee46e4df4e7db1e6bfcf2fcc9f0c86878cb86707Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz470w:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    90c790ad-c40e-4527-8f83-d278282a9600
NVD CPE · HARDWAREsonicwalltz570Environmental constraint · 1 assertions
Version not applicableCanonical identity product-644cc31432cf11275df8bda5ede1c6d8ce83bb1349fd95f0f0b3fcc4ded5fcebLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz570:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c7df76e0-8e3d-4e0d-a3bb-f5ae05a4c7c9
NVD CPE · HARDWAREsonicwalltz570pEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-6d8bafcc3f830c20a17b9a5665182f8616650ebc680e62eca59b25143620973cLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz570p:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    352dfcf9-e333-41c0-8033-91265768fd8e
NVD CPE · HARDWAREsonicwalltz570wEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-31ab8c8847a1672604957cd899b3a3390ad809900bd0bb3b38f646f8ebe8f296Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz570w:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4c882c38-9da5-4c03-bb23-ab2b448e3307
NVD CPE · HARDWAREsonicwalltz670Environmental constraint · 1 assertions
Version not applicableCanonical identity product-703edd6cdd5765e5d8edbf29d3318bb1fc8b19c81cbe867c1bf7b34f66fb4836Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz670:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aeea6065-48d3-4ec7-bd94-cbae3d1010ff
NVD CPE · HARDWAREsonicwalltz80Environmental constraint · 1 assertions
Version not applicableCanonical identity product-51804fd2fb0fcda2ab1ee1cb4067514b7de3998f37352ed0720615e8883003d9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:sonicwall:tz80:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    129cc10f-e822-4bf7-9eb5-0d702020cb0c

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 2 source-reported links

Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
edb254be-2a04-4371-92ea-b6232a138433
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4b078987-15cf-40cd-a5f5-df13f1d29709b62b9547-1ce6-4caa-90df-d40737b50e38b8b0d6f0-9b9b-41cf-9603-64332f4bc903

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
8.2
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
8.2
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Direct CVE/CNA normalized decisions

8.2Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Validation
Valid match
Recomputed
8.2
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.