CVE-2024-12802 is a critical (CVSS 9.1) MFA bypass vulnerability in SonicWall Gen6 SSL-VPN devices that stems from separate authentication handling of UPN and SAM account formats. Even after applying firmware patches, Gen6 devices remain vulnerable unless a six-step manual LDAP reconfiguration is completed — a step that standard patch management workflows typically skip. Attackers exploiting this flaw can authenticate without triggering MFA, with bypass events logged as legitimate MFA successes, making detection difficult. Ransomware-linked attacks exploiting this vulnerability were observed in early 2026. As of May 2026, approximately 6,250 SonicWall SSL-VPN instances are publicly accessible on the internet. Remediation for Gen6 devices requires removing legacy LDAP configurations using userPrincipalName, clearing cached LDAP users, resetting SSL-VPN User Domain settings, rebooting, and creating new clean backups. Gen6 devices reached end-of-support on April 16, 2026, making migration to supported hardware a long-term priority.

9m read timeFrom infosecwriteups.com
Post cover image
Table of contents
Understanding CVE-2024–12802: An Overview of the VulnerabilityAnalyzing the Root Cause: Separate MFA Validation Paths for UPN and SAMMapping the Attack Flow Behind the VulnerabilityDiscovering Publicly Accessible SonicWall SSL-VPN Systems with Criminal IPGet Criminal IP ’s stories in your inboxSecurity Mitigation Guidance and Best PracticesConclusion
98 Impressions