CVE-2023-1101

SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
sonicwallCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
sonicwallsonicos
𝑥
< 7.0.1-5111
sonicwallsonicos
𝑥
≤ 7.0.1-5083
sonicwallsonicos
𝑥
≤ 6.5.4.4-44v-21-1551
sonicwallsonicos
𝑥
≤ 6.5.4.11-97n
𝑥
= Vulnerable software versions