CVE-2024-53704
CRITICAL KEV RANSOMWARE NUCLEISonicOS >=7.1.1-7040 <7.1.1-7058 - Unauthenticated Authentication Bypass via SSLVPN
Title source: llmExploitation Summary
CVE-2024-53704 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 18, 2025, with confirmed use in ransomware campaigns. EIP tracks 4 public exploits from researchers including istagmbh, anir0y, spicy-bear. A Nuclei detection template is also available.
AI-analyzed exploit summary This PoC exploits CVE-2024-53704, an authentication bypass vulnerability in SonicWALL NetExtender VPN. It skips the login process by injecting a stolen 'swap' cookie and establishes a VPN session, allowing unauthorized access to the VPN tunnel.
Description
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Exploits (4)
This PoC exploits CVE-2024-53704, an authentication bypass vulnerability in SonicWALL NetExtender VPN. It skips the login process by injecting a stolen 'swap' cookie and establishes a VPN session, allowing unauthorized access to the VPN tunnel.
This repository contains a functional exploit for CVE-2024-53704, an authentication bypass vulnerability in SonicWall SSLVPN via cookie forgery. It includes a Docker-based lab environment with vulnerable containers for testing, along with working exploit code and detailed walkthroughs.
The repository contains functional exploit code for CVE-2024-53704, targeting a session hijacking vulnerability in a web application via a crafted cookie. The exploit sends a GET request with a base64-encoded cookie to trigger the vulnerability.
This PoC exploits CVE-2024-53704 by brute-forcing session cookies to leak valid session IDs from a target system. It uses a checksum calculation to generate valid cookies and checks their validity via an API endpoint.
Nuclei Templates (1)
http.html_hash:-1466805544
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H