Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
2023-12-05T21:15:07.667
2024-11-21T08:42:53.403
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sonicwall | sma_200_firmware | ≤ 10.2.1.9-57sv | Yes |
Hardware | sonicwall | sma_200 | - | No |
Operating System | sonicwall | sma_210_firmware | ≤ 10.2.1.9-57sv | Yes |
Hardware | sonicwall | sma_210 | - | No |
Operating System | sonicwall | sma_400_firmware | ≤ 10.2.1.9-57sv | Yes |
Hardware | sonicwall | sma_400 | - | No |
Operating System | sonicwall | sma_410_firmware | ≤ 10.2.1.9-57sv | Yes |
Hardware | sonicwall | sma_410 | - | No |
Operating System | sonicwall | sma_500v_firmware | ≤ 10.2.1.9-57sv | Yes |
Hardware | sonicwall | sma_500v | - | No |