Criminal IP[verified]@CriminalIP_USPatch
The post highlights that firmware patches alone do not secure SonicWall SSL‑VPN devices, emphasizing the need for manual LDAP reconfiguration and appearing to provide a workaround rather than a proof of concept or exploit.
Cyber News Live[verified]@cybernewsliveActive Exploitation
A hacking gang (Akira) is actively exploiting a login bypass flaw (CVE‑2024‑12802) on SonicWall VPNs, bypassing patch updates and MFA, and the fix requires additional manual steps on older devices.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE‑2024‑40766 is actively exploited by Akira and Fog ransomware; firmware patches alone do not remediate the issue, requiring manual LDAP reconfiguration and addressing stale accounts and exposed MFA portals.
DFIR Radar[verified]@DFIR_RadarDisclosure
The note highlights that CVE-2024-12802 is a high‑risk MFA bypass flaw in SonicWall Gen6 SSL‑VPN. It points out that firmware patches alone are insufficient and that a manual 6‑step LDAP reconfiguration is needed to fully remediate the vulnerability.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The post reports active exploitation of CVE-2024-12802, notes its high severity and MFA bypass mechanism, and indicates vendor patches exist but require manual configuration changes.
ReliaQuest Threat Research[verified]@ReliaQuestTRActive Exploitation
The passage reports the first real‑world exploitation of CVE‑2024‑12802 on SonicWall SSL VPN, detailing how attackers brute‑forced credentials, bypassed MFA, and noting that manual LDAP reconfiguration is required as a workaround.
Elusive[verified]@ElusivePrivacyActive Exploitation
The post reports active exploitation of the SonicWall VPN MFA bypass in the wild, noting incomplete patching of CVE-2024-12802 and rapid ransomware deployment following credential brute‑force.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE-2024-12802 allows MFA bypass on SonicWall Gen6 SSL‑VPN appliances; ReliaQuest reports active exploitation by ransomware‑using access brokers, with log indicators sess="CLI" and event IDs 238/1080.