Evidence dossier
CVE-2024-53704
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Exploited in the wild (CISA KEV since Feb 18, 2025). NVD reports CVSS 3.1 9.8. Severity assessments differ within at least one CVSS version. EPSS estimates 95.1% exploit likelihood as of Jul 31, 2026.
As of Aug 27, 2026
Normalized restatement
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
- State
- PUBLISHED
- Published
- Jan 9, 2025
- Updated
- Aug 4, 2026
- Evidence coverage
- 72%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 95.13% probability · 99.86th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.951320000000; percentile 0.998560000000
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAsonicwallOriginal evidence ↗
Record text: An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Inspect raw assertion
- Field
container- Value
- An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date Feb 18, 2025 · first observed Jul 19, 2026
FIRST EPSS · score date Jul 31, 2026 · 99.9th percentile · first observed Aug 1, 2026
NVD · CVSS 3.1 · first observed Aug 4, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve conflict
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
95.13% probability · 99.86th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.951320000000; percentile 0.998560000000
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Inspect raw assertion
- Field
container- Value
- An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Applicability
Cited product scope
Grouped from 4 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
25 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "7.1.1-7058 and older versions"}, {"status": "affected", "version": "7.1.2-7019"}, {"status": "affected", "version": "8.0.0-8035"}]product-673117bd8776e02e74068c74394f87a86cc3e426fb4bb297b07a7a02abbfd557Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d8b0c7a-fd65-47ca-a625-150a90efa7a1
product-5a3fa65e2a189c8facfc0c4f6473b5806e2d32806948bf49b33caf920338b257Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a69e000b-5806-46fd-a233-4e2cc9dd38d2
product-239c8e8ef47d51bb08cb8337dddb1caf08aafe251e81b532c5f9761b09bf4c1aLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8df4a322-7cc7-4ab9-b10e-fff34df2182d
product-dee1d892c41f618914799c2e8782f436cdb306f8b5b02803ca8e50ffbe420ebdLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c15fed5-c48c-47cf-9645-0563d77883c1
product-5888cbc14bd3d33584c779cd787b2cf3af831c2018711369f070f86181980e10Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a884b1bb-f201-4c77-9f6e-b8a884dcd4c2
product-583608ad2eed376bf7f5d8e7f14a16d915747e91e3d430e485b95fbb508409e5Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7c3ba5a3-1160-4793-a8d6-40b9d264bcc4
product-60cff82ad64a904b621b4400d6cb5153d34299272fea11f4df46fac46ab61b5cLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6739dea3-06ff-4feb-9931-0db27f63b70e
product-5effcb3c3c55f05592e2f2712cda9b00156edc998efaea8731637b4db7f430d8Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0250edf9-0aef-4711-8ef6-d447cf48bcaf
product-e41f245c444aeb7286921d443f470a96a7c13aabab9a84c9cc0496aaa626b00eLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nssp_15700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7d6cf3cf-256c-4c04-8bdf-b16398cd0459
product-8292184067857470da2371294fe91de9b412835f57b2c064f1a009249e575645Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsv_270:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f2abc8d8-2943-4073-9568-e87961a18998
product-d16a47ccd8acb9353db836069888ae8cbd064435942e5beadee83bae51f3d31fLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsv_470:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f57d527-aa3f-45e9-9bce-6f76691066b5
product-d628a0dc74e75cd37ba092a3f0406b87c1c27389b08d54c3c40add950dab2021Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:nsv_870:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f5ecccf0-a5d8-42a8-8ec1-d12b49b1124a
product-85898d6fe491d9f6f381bbdf2d6cef63a8d780eebbf13fe9fb76aeb30af6b3d7Linked exactInspect raw assertions
cpe:2.3:o:sonicwall:sonicos:7.1.2-7019:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0131b5d1-47ff-4a35-8983-7c08e021f7a4
cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 7.1.1-7040; through including 7.1.1-7058
- Match ID
065dd610-7821-4a0e-9cc8-1255f1729126
cpe:2.3:o:sonicwall:sonicos:8.0.0-8035:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
495254b3-5733-467e-aaa0-a9d385328c8e
product-23a7b086ae83d780a3f91a4ce4cbf4ea1844edbc00b631cc1e2666ffff08385dLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz270:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
70340dd4-687b-402c-85af-c2b80d0f1600
product-3a897e8969dc90bf02e979f957d908e561ecd1cac3feb21ff8489f7166e6b069Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz270w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
52847ba2-470b-4078-a79b-52095db9214b
product-3c9a8e100503fe45fe731c0bde2acceb764b7bfb554755d6c18dc3cbcfe91b07Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz370:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9853ae3a-b0ea-4249-aa7d-1f2051c9bf91
product-857f02f449eef288d4709b6a06edc69b9b916c372d90424fbe3657fc17341161Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz370w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4dbdd10c-f89d-4051-bc70-67b41167ff9b
product-0362aebe42896e7a4ab46a8b15f961c6853cc46c0b5f5a9d320e0ddeb7b9fa52Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz470:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c23940e-2f9d-447b-a740-42035ed5d400
product-458561e75a93fac8630fff75ee46e4df4e7db1e6bfcf2fcc9f0c86878cb86707Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz470w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
90c790ad-c40e-4527-8f83-d278282a9600
product-644cc31432cf11275df8bda5ede1c6d8ce83bb1349fd95f0f0b3fcc4ded5fcebLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz570:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c7df76e0-8e3d-4e0d-a3bb-f5ae05a4c7c9
product-6d8bafcc3f830c20a17b9a5665182f8616650ebc680e62eca59b25143620973cLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz570p:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
352dfcf9-e333-41c0-8033-91265768fd8e
product-31ab8c8847a1672604957cd899b3a3390ad809900bd0bb3b38f646f8ebe8f296Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz570w:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c882c38-9da5-4c03-bb23-ab2b448e3307
product-703edd6cdd5765e5d8edbf29d3318bb1fc8b19c81cbe867c1bf7b34f66fb4836Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz670:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aeea6065-48d3-4ec7-bd94-cbae3d1010ff
product-51804fd2fb0fcda2ab1ee1cb4067514b7de3998f37352ed0720615e8883003d9Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:tz80:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
129cc10f-e822-4bf7-9eb5-0d702020cb0c
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 2 source-reported links
Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
edb254be-2a04-4371-92ea-b6232a138433Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4b078987-15cf-40cd-a5f5-df13f1d29709b62b9547-1ce6-4caa-90df-d40737b50e38b8b0d6f0-9b9b-41cf-9603-64332f4bc903Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H- Validation
- Valid match
- Recomputed
- 8.2
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.