As cited
Copy frozen at (site build).
vulnerabilities
VPN Exploitation When Patched Doesn't Mean Protected
CVE-2024-12802 is an authentication bypass vulnerability in SonicWall SSL VPN appliances that reduces security to single-factor authentication and bypasses MFA. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, yet standard patch management workflows do not verify these steps, leaving devices appearing patched while remaining exploitable. ReliaQuest identified in-the-wild exploitation of this vulnerability between February and March 2026, where threat actors brute-forced VPN credentials and deployed ransomware staging tools within 30 minutes of initial access.
Why it matters: Organizations running SonicWall Gen6 SSL VPN appliances are at immediate risk if they patched based on firmware version alone without completing six manual remediation steps; practitioners should verify all required configuration changes and implement detection for the sess="CLI" session type to identify brute-force attacks early before ransomware actors gain network access.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
VPN Exploitation When Patched Doesn't Mean Protected
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
VPN Exploitation When Patched Doesn't Mean Protected
ReliaQuest identified exploitation of CVE-2024-12802, an authentication bypass in SonicWall SSL virtual private network (VPN) appliances, between February and March 2026. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, leaving patched devices fully exploitable. Attackers brute-forced VPN credentials and bypassed multifactor authentication (MFA) to gain internal network access, with some intrusions deploying ransomware staging tools within 30 minutes of initial access.
Why it matters: Organizations running SonicWall Gen6 appliances are at risk if they relied on firmware patching alone to remediate CVE-2024-12802, as the vulnerability remains exploitable without manual reconfiguration steps; immediate verification of all six Gen6 remediation steps and monitoring for the sess='CLI' session type in VPN logs are required to detect and block active exploitation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
VPN Exploitation When Patched Doesn't Mean Protected
ReliaQuest identified exploitation of CVE-2024-12802, an authentication bypass in SonicWall SSL virtual private network (VPN) appliances, between February and March 2026. On Gen6 devices, the firmware patch alone does not remediate the vulnerability; six additional manual reconfiguration steps are required, leaving patched devices fully exploitable. Attackers brute-forced VPN credentials and bypassed multifactor authentication (MFA) to gain internal network access, with some intrusions deploying ransomware staging tools within 30 minutes of initial access.
Why it matters: Organizations running SonicWall Gen6 appliances are at risk if they relied on firmware patching alone to remediate CVE-2024-12802, as the vulnerability remains exploitable without manual reconfiguration steps; immediate verification of all six Gen6 remediation steps and monitoring for the sess='CLI' session type in VPN logs are required to detect and block active exploitation.
- Source published
- First seen by Cybersecurity Tracker