ZeroHour

CVE-2023-5970

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
Description

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.

Vendors
sonicwall
Products
sma 200 firmware, sma 210 firmware, sma 400 firmware, sma 410 firmware, sma 500v firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.