boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-40766

SonicWall SonicOS
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .1838   97.2   YES
AFFECTED
  Product  Versions                           Fixed
  SonicOS  5.9.2.14-12o and older versions –  —
TIMELINE
  Jul 10  Reserved by sonicwall
  Aug 23  Published (CNA: sonicwall)
  Sep 9   Added to CISA KEV, remediation due 2024-09-30
  Sep 21  RESCORED — CVE-2024-40766 (SonicWall SonicOS). CVSS 9.3 → 9.8 (NVD).
CWE-284 · CNA: sonicwall · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due September 30, 2024

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
July 10, 2024ReservedReserved by sonicwall
August 23, 2024PublishedPublished (CNA: sonicwall)
September 9, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-09-30
September 21, 2026RESCOREDRESCORED — CVE-2024-40766 (SonicWall SonicOS). CVSS 9.3 → 9.8 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
SonicWallSonicOS—5.9.2.14-12o and older versions—

Weaknesses

CWE-284

References (2)

Related

Authoritative record: CVE-2024-40766 at cve.org

Vendors: sonicwall

Weaknesses: CWE-284

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-40766 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Monday, October 5, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.