CVE-2024-40764

EUVD-2024-38612
Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
sonicwallsonicos
𝑥
< 6.5.4.v-21s-rc2457
sonicwallsonicos
𝑥
< 7.0.1-5161
sonicwallsonicos
7.1.1-7040 ≤
𝑥
< 7.1.1-7058
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
sonicwallsonicos
𝑥
≤ 6.5.4.4-44v-21-2395
ADP
sonicwallsonicos
𝑥
≤ 7.0.1-5151
ADP
sonicwallsonicos
𝑥
≤ 7.1.1-7051
ADP