CVE-2024-53705 Details
Description
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establish a TCP connection to an IP address on any port when the user is logged in to the firewall.
A server-side request forgery (SSRF) vulnerability has been identified in the SonicOS SSH management interface. This vulnerability allows remote attackers to establish TCP connections to any IP address and port while the user is logged into the firewall. The issue affects multiple SonicWall firewall products across different generations and versions.
Users are advised to update to the latest patched versions available. For Gen6 hardware firewalls, the fixed version is 6.5.5.1-6n and higher. For Gen7 firewalls and NSv, the fixed versions are 7.0.1-5165 and higher or 7.1.3-7015 and higher. For TZ80, the fixed version is 8.0.0-8037 and higher. If an immediate update is not possible, consider disabling SSH management access from the Internet.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 9, 2025CISA-ADP
Assessed Jan 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SonicWall SonicOS | All versions |
CPE
Remediation
| |
| SonicWall Gen6 Hardware Firewalls | All versions |
CPE
Remediation
| |
| SonicWall Gen7 Firewalls | All versions |
CPE
Remediation
| |
| SonicWall Gen7 NSv | All versions |
CPE
Remediation
| |
| SonicWall TZ80 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 9, 2025 | CVE Modified | CISA-ADP |
| Jan 9, 2025 | New CVE Received | [email protected] |
Volerion