CVE-2023-1101

SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
sonicwallsonicos
𝑥
< 7.0.1-5111
sonicwallsonicos
𝑥
≤ 7.0.1-5083
sonicwallsonicos
𝑥
≤ 6.5.4.4-44v-21-1551
sonicwallsonicos
𝑥
≤ 6.5.4.11-97n
𝑥
= Vulnerable software versions