SonicWall issued fixes for multiple high-severity SonicOS vulnerabilities affecting Gen6, Gen7, NSv, and TZ80 firewalls, led by CVE-2024-53704, a critical SSL VPN authentication bypass that lets a remote, unauthenticated attacker hijack an active VPN session with a crafted session cookie. Successful exploitation can give an attacker the victim’s internal network access, expose Virtual Office bookmarks, allow retrieval of a NetExtender client profile, and enable establishment of a VPN tunnel; the attacker can also terminate the legitimate user’s session. Additional patched flaws include privilege escalation, token prediction that can lead to unauthorized access, and SSRF through the SSH management interface.
Bishop Fox later published technical analysis and a working exploit for CVE-2024-53704, reporting that exploitation becomes trivial once the flaw is understood and relies on crafted Base64-encoded session cookies containing null bytes. The researchers said roughly 4,500 internet-facing SonicWall SSL VPN servers remained unpatched in early February 2025, increasing exposure, while CSIRT.SK warned that public exploit details raise the likelihood of targeted attacks. SonicWall and downstream defenders urged immediate firmware upgrades and tighter restriction of firewall management interfaces, noting that detection is difficult but that SSL VPN logs showing the same session used from multiple source IP addresses may indicate hijacking.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Bishop Fox demonstrated practical exploitation of CVE-2024-53704, showing that a remote unauthenticated attacker can hijack active SonicWall SSL VPN sessions using crafted Base64-encoded session cookies containing null bytes. The publication also described post-hijack access possibilities such as reaching internal networks, reading bookmarks, retrieving NetExtender profiles, and establishing a VPN tunnel.
As of February 7, 2025, Bishop Fox reported that internet scans identified roughly 4,500 internet-facing SonicWall SSL VPN servers that remained unpatched for CVE-2024-53704. The finding highlighted continued exposure after SonicWall's fixes were available.
On January 7, 2025, SonicWall published advisory SNWLID-2025-0003 and released security updates for SonicOS-based firewalls addressing four high-severity vulnerabilities, including CVE-2024-53704 in SSL VPN. The advisory initially stated there was no evidence of in-the-wild exploitation and urged administrators to apply firmware updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcebishopfox.com
Open sourcepsirt.global.sonicwall.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.