Sonicwall VPN Error could allow hackers to hijack your sessions, so patch now


  • Bishop Fox found a way to abuse a Sonicwall VPN error
  • It allows threat actors to bypass approval and hijacking sessions
  • There are thousands of vulnerable endpoints

A great vulnerability in Sonicwall VPN, which can be utilized to hijack sessions and access the target network, has now seen its first proof-of-concept (POC) attack, which means it is only a matter of time before cyber criminals begins to exploit it in nature.

At the beginning of January 2025, Sonicwall raised the alarm on a vulnerability in Sonicos and urged its users to apply the correction immediately. The error is traced as CVE-2024-53704 and is described as an incorrect approval error in the SSLVPN approval mechanism. It got a severity of 9.8/10 (critical) and was said that it could be abused to allow an external striker to bypass approval.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top