Tech

SonicWall VPN flaw could allow hackers to hijack your sessions, so patch now

Share
Share


  • Bishop Fox found a way to abuse a SonicWall VPN flaw
  • It allows threat actors to bypass authentication and hijack sessions
  • There are thousands of vulnerable endpoints

A major vulnerability in the SonicWall VPN which can be exploited to hijack sessions and access the target network has now seen its first proof-of-concept (PoC) attack, meaning it’s only a matter of time before cybercriminals start exploiting it in the wild.

In early January 2025, SonicWall raised the alarm on a vulnerability in SonicOS and urged its users to apply the fix immediately. The flaw is tracked as CVE-2024-53704, and described as an Improper Authentication bug in the SSLVPN authentication mechanism. It was given a severity score of 9.8/10 (critical) and was said it could be abused to allow a remote attacker to bypass authentication.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Microsoft reportedly set to cut thousands of jobs, with sales roles particularly at risk
Tech

Microsoft reportedly set to cut thousands of jobs, with sales roles particularly at risk

Microsoft reportedly set to lay off thousands in its new fiscal year...

Waymo looks to test its self-driving cars in New York
Tech

Waymo looks to test its self-driving cars in New York

Human drivers will remain at the wheel in Waymo self-driving cars once...