SonicWALL SSLVPN是美国SonicWALL公司的一个适用于 Windows 和 Linux 用户的透明软件应用程序。使远程用户能够安全地连接到公司网络。 SonicWALL SSLVPN存在安全漏洞,该漏洞源于身份验证不当。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | demonstriert, wie mittels missbräuchlicher Nutzung eines Swap-Cookies eine VPN-Session übernommen werden kann. Wichtig: Dieses Projekt dient ausschliesslich zu Bildungs- und Forschungszwecken – bitte nur in Umgebungen verwenden, in denen Du explizit authorisiert bist. | https://github.com/istagmbh/CVE-2024-53704 | POC Details |
| 2 | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-53704.yaml | POC Details |
| 3 | Exploit for CVE-2024-53704 - SonicWall SonicOS SSLVPN authentication bypass | https://github.com/sfewer-r7/SonicSessionLeak | POC Details |
| 4 | SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704) | https://github.com/anir0y/sonicwall-audit-toolkit | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-12806 | SonicWALL SonicOS 安全漏洞 | |
| CVE-2024-12802 | SonicWALL SSL-VPN 安全漏洞 | |
| CVE-2024-12805 | SonicWALL SonicOS 安全漏洞 | |
| CVE-2024-12803 | SonicWALL SonicOS 安全漏洞 | |
| CVE-2024-40765 | SonicWALL SonicOS 安全漏洞 | |
| CVE-2024-40762 | SonicWALL SonicOS 安全漏洞 | |
| CVE-2024-53705 | SonicWALL SonicOS 安全漏洞 | |
| CVE-2024-53706 | SonicWALL Gen7 SonicOS Cloud platform NSv 安全漏洞 |
No comments yet