Critical Vulnerability

CVE-2024-40766: Patch fixed bug, not config risk

By Yazoul AI · automated

The vulnerability 

What Happened

A critical vulnerability in Sophos Firewall, tracked as CVE-2024-40766, was patched in mid-2024, but attackers continue to exploit organizations who applied the patch without addressing the underlying insecure default configuration. The flaw, which initially enabled remote code execution, was remediated in a firmware update. However, the SANS Internet Storm Center reports that the real threat persists: the patch fixed the code, but the vulnerable configuration - specifically, exposing the firewall’s admin interface and user portal to the WAN - remains unchanged in many deployments.

Why It Matters

This case highlights a recurring blind spot in vulnerability management: patching the software does not fix the architectural risk. Organizations that deployed the firmware update assumed they were secure, but attackers are now bypassing the patched code by leveraging the same exposed services that made CVE-2024-40766 exploitable in the first place. The result is a false sense of security, where patched systems remain compromised due to unchanged network exposure.

Technical Details

CVE-2024-40766 affects Sophos Firewall versions 18.x and earlier, with an CVSS score of 9.8 (Critical). The vulnerability resided in the firewall’s user portal and webadmin interface, allowing unauthenticated attackers to execute remote code. The patch corrected the code-level flaw, but the root cause - these services being accessible from the internet - was not addressed. Attackers are now observed scanning for firewalls that still have the admin interface or user portal exposed to the WAN, even on fully patched versions. Once found, they can pivot to other post-exploitation activities such as credential theft or lateral movement.

Immediate Risk

Organizations running patched Sophos Firewalls with any management interface accessible from the internet remain at high risk. The attack surface is not eliminated by the patch alone; any WAN-exposed admin or user portal is a viable entry point. The most common misconfiguration is leaving the webadmin interface on port 4444 or 8443 open to “Any” on the WAN zone. The risk is amplified because security teams often lack visibility into firewall config drift post-patching.

Security Insight

The Sophos CVE-2024-40766 aftermath mirrors a pattern seen in 2021 with Fortinet’s CVE-2018-13379: a patched SSL VPN flaw that continued to give attackers access because organizations never disabled the vulnerable SSL-VPN portal on their firewalls. The defensive takeaway is that patch management must be coupled with a mandatory “post-patch hardening review” - a discrete step where teams verify that the vulnerable service is no longer exposed to untrusted networks. Without this, a patched CVE is simply a rested attack surface, not a remediated one.

Further Reading

Share:

Never miss a security update

Get real-time security alerts delivered to your preferred platform.

Related News

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.