Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SonicWall’s December 2024 security notice covers SMA 100 series SSL-VPN appliances running firmware 10.2.1.13-72sv or earlier. The reported fixed release is 10.2.1.14-75sv. SMA1000 SSL VPN products are excluded from this specific set of vulnerabilities.

Which SonicWall appliances and firmware are affected?

The reported scope is the SMA 100 series running firmware 10.2.1.13-72sv or earlier. The report identifies 10.2.1.14-75sv as the release containing the fixes. These version details come from SecurityWeek’s December 6, 2024 coverage of SonicWall’s notice; administrators should also check the current SonicWall PSIRT advisory SNWLID-2024-0018 and the release documentation for their appliance model before deploying firmware, since later vendor guidance is not established here.

SMA1000 SSL VPN products are not affected by this specific vulnerability set. Do not apply the SMA 100 version information to an SMA1000 appliance.

What are the six vulnerabilities?

The set includes three buffer overflows, along with flaws involving path handling, certificate requirements, and backup-code generation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SonicWall Firewall SSL VPN - License - 100 Users (01-SSC-6112) - Secure Remote Access for Encrypted, Policy-Controlled Connectivity Across Any Device
  • SonicWall Firewall SSL VPN - License (01-SSC-6112)
  • Secure Remote User Access: Enables encrypted VPN connections to SonicWall firewalls for users working from home, on the road, or at branch locations.
  • Clientless Browser-Based VPN: Users can securely access internal resources through web browsers without requiring a dedicated VPN client.
  • Policy-Based Access Controls: Enforce granular access by user, device, time, or application with full integration into LDAP, AD, or RADIUS.
  • Supports Windows, macOS, and Mobile Devices: Ensure secure access across diverse platforms, including laptops, tablets, and smartphones.
CVE Issue and reported consequence Severity information
CVE-2024-45318 Stack-based buffer overflow in the web management interface; a remote attacker could potentially achieve code execution. CVSS 8.1, as reported by SecurityWeek.
CVE-2024-53703 Stack-based buffer overflow in a library loaded by Apache; a remote attacker could potentially achieve code execution. CVSS 8.1, as reported by SecurityWeek.
CVE-2024-40763 Heap-based buffer overflow related to strcpy; exploitation requires authentication and could potentially lead to code execution. CVSS v3 7.5, listed by Tenable.
CVE-2024-38475 Path traversal flaw in Apache HTTP Server, affecting how URLs are mapped to file-system locations permitted to be served. Not stated in the cited coverage.
CVE-2024-45319 A remote authenticated attacker could circumvent certificate requirements during authentication. Not stated in the cited coverage.
CVE-2024-53702 A cryptographically weak pseudo-random number generator in the SMA 100 SSLVPN backup-code generator could, in certain cases, make a generated secret predictable. Not stated in the cited coverage.

The CVSS figures above are the ratings reported by SecurityWeek for the two stack overflows and by Tenable for CVE-2024-40763; they are not a fresh assessment of risk for a particular installation. The available reporting does not give a severity score for the other three entries.

What should administrators do?

  1. Confirm the product family. Verify that the appliance is an SMA 100 series device, not an SMA1000.
  2. Check the installed firmware. If it is 10.2.1.13-72sv or earlier, it falls within the reported affected range.
  3. Review current vendor guidance. Consult the SonicWall PSIRT advisory and model-specific release documentation for the applicable firmware and deployment procedure.
  4. Plan the update. The report identifies 10.2.1.14-75sv as the fixed release and advises updating affected appliances as soon as possible. Follow the vendor’s current instructions for your model.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about exploitation?

SecurityWeek reported on December 6, 2024, that SonicWall said it had no evidence of exploitation in the wild at that time. That is a historical statement, not confirmation of the current threat status. Check the current vendor advisory for any later updates.

Rank #4
SonicWall Gateway Anti-Malware, Intrusion Prevention & Application Control for NSA2700-1 Year License (02-SSC-6929) - Real-Time Threat Protection & Deep Network Visibility
  • SonicWall Gateway Anti-Malware, Intrusion Prevention & Application Control for NSA2700 - 1 Year License (02-SSC-6929)
  • Real-Time Malware Scanning: Block viruses, spyware, and ransomware at the gateway before they reach endpoints or servers.
  • Intrusion Prevention System (IPS): Detect and stop network-based attacks, exploits, and denial-of-service attempts using constantly updated threat signatures.
  • Application Intelligence & Control: Identify, monitor, and restrict the use of applications to enforce policies and reduce bandwidth abuse.
  • Low-Latency Deep Packet Inspection: Analyze traffic without slowing performance, using SonicWall's patented Reassembly-Free DPI engine.
Rank #3
SonicWall Gateway Anti-Malware, Intrusion Prevention & Application Control for TZ370W - 3 Year License (02-SSC-6597) - Real-Time Threat Protection & Deep Network Visibility
  • SonicWall Gateway Anti-Malware, Intrusion Prevention & Application Control for TZ370W - 3 Year License (02-SSC-6597)
  • Real-Time Malware Scanning: Block viruses, spyware, and ransomware at the gateway before they reach endpoints or servers.
  • Intrusion Prevention System (IPS): Detect and stop network-based attacks, exploits, and denial-of-service attempts using constantly updated threat signatures.
  • Application Intelligence & Control: Identify, monitor, and restrict the use of applications to enforce policies and reduce bandwidth abuse.
  • Low-Latency Deep Packet Inspection: Analyze traffic without slowing performance, using SonicWall's patented Reassembly-Free DPI engine.
Rank #2
SonicWall Global VPN Client - License - 100 Licenses (01-SSC-5314) - Secure IPsec VPN Connectivity for Remote Work & Site-to-Site Access
  • SonicWall Global VPN Client - License (01-SSC-5314)
  • Secure IPsec VPN Access: Enables encrypted remote connections to SonicWall firewalls using robust IPsec tunneling protocols.
  • Consistent Remote Access Experience: Delivers a reliable and high-performance VPN connection for employees working remotely or from branch sites.
  • Compatible with Windows OS: Designed for Microsoft Windows environments, with simple installation and configuration.
  • Policy-Based Access Control: Enforce connection rules and restrict access to resources based on user identity and endpoint status.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.