More

    SonicWall VPN flaw could allow hackers to hijack your sessions, so patch now




    • Bishop Fox found a way to abuse a SonicWall VPN flaw
    • It allows threat actors to bypass authentication and hijack sessions
    • There are thousands of vulnerable endpoints

    A major vulnerability in the SonicWall VPN which can be exploited to hijack sessions and access the target network has now seen its first proof-of-concept (PoC) attack, meaning it’s only a matter of time before cybercriminals start exploiting it in the wild.

    In early January 2025, SonicWall raised the alarm on a vulnerability in SonicOS and urged its users to apply the fix immediately. The flaw is tracked as CVE-2024-53704, and described as an Improper Authentication bug in the SSLVPN authentication mechanism. It was given a severity score of 9.8/10 (critical) and was said it could be abused to allow a remote attacker to bypass authentication.

    https://cdn.mos.cms.futurecdn.net/ji5q5LEbkXwmbhvpgHgPqK-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img