A newly disclosed zero-day vulnerability (CVE-2024-53704) in SonicWall’s SonicOS is actively being exploited in the wild, allowing attackers to hijack SSL VPN sessions without credentials. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch by March 11, 2025.
Read the Technical Analysis
HERE.
✅ Apply Vendor Patches – Update to the latest SonicOS versions immediately.
✅ Enforce Multi-Factor Authentication (MFA) – Prevent unauthorized access to VPN sessions.
✅ Restrict SSL VPN Access – Allow connections only from trusted IP ranges.
✅ Reset Credentials & Strengthen Password Policies – Secure locally managed SSLVPN accounts.
✅ Monitor VPN Activity – Watch for unusual login behavior and unauthorized access attempts.
ABT Solutions provides 24/7 security monitoring, Enterprise Grade Endpoint and Email Security, real-time threat intelligence, and compliance-driven vulnerability management to protect your network from active exploits. Our solutions include:
For assistance securing your organization, contact ABT Solutions, LLC today.
Dedicated to Your Security,
Braden A. Lampe - CEO @ ABT Solutions, LLC
Awesome! You will be added to our Threat Intelligence Email Alerts.
Oops, there was an error. Please try again later.
All Rights Reserved | ABT Solutions, LLC