When you purchase through links on our site, we may earn an affiliate commission.Heres how it works.

The flaw is tracked as CVE-2024-53704, and described as an Improper Authentication bug in the SSLVPN authentication mechanism.

It impacted SonicOS versions 7.1.x (up to 7.1.1-7058), 7.1.2-7019, and 8.0.0-8035.

A VPN runs on a mobile phone placed on a laptop keyboard

At the time, there were more than 4,500 internet-exposed endpoints.

Protect yourself from identity theft online

Go Incogni and get 55% off using code TECHRADAR.

Incogni erases you and your family from the sites that expose your personal information to identity thieves and robocalls.

Protect yourself from identity theft online

Preferred partner (What does this mean?)

This results in the endpoint assuming the request was associated with an active VPN session and incorrectly validates it.