CVE-2024-53704
CISA KEVRansomwareAs of 2026-02-26, CVE-2024-53704 is a CVSS 8.2 (HIGH-severity) vulnerability. CISA KEV-listed (known exploited); Public exploit code available; Nuclei detection template exists. EPSS exploitation probability 95.1%. Threadlinqs Intelligence tracks 3 threats exploiting it.
Last updated: 2026-02-26
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Weaknesses (CWE)
CWE-287
Exploitation status
CISA KEV-listed (known exploited) · public exploit code available · nuclei detection template exists
- istagmbh/CVE-2024-53704 (github)
- sfewer-r7/SonicSessionLeak (github)
- anir0y/sonicwall-audit-toolkit (github)
- trickest/cve (trickest)
Threats tracking this CVE
- US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations — HIGH
- Sinobi Ransomware: Curve-25519/AES-128-CTR Encryption with Shadow Copy and Backup Destruction (Lynx/INC Rebrand) — HIGH
- Coordinated Reconnaissance Campaign Maps SonicWall SSL VPN Attack Surface via Commercial Proxy Infrastructure (84,142 Sessions / 4,305 IPs / 20 ASNs) — HIGH
References
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.