SonicWall SonicOS Flaw Confirmed to be Exploited In-the-Wild After PoC Release

On February 10, 2025, Bishop Fox researchers released proof-of-concept (PoC) exploit code for CVE-2024-53704 which affects SonicWall firewalls running SonicOS firmware versions 7.1.x (7.1.1-7058 and older), 7.1.2-7019, and 8.0.0-8035.

The vulnerability allows remote unauthenticated threat actors to hijack active SSL VPN client sessions. Successful exploitation can allow threat actors to view Virtual Office bookmarks, acquire NetExtender client configuration profiles, establish a VPN tunnel, access private networks accessible to the compromised account, and terminate the user’s sessions.

View the details below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272