CVE-2023-5970
05.12.2023, 21:15
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.Enginsight
Vendor | Product | Version |
---|---|---|
sonicwall | sma_200_firmware | 𝑥 ≤ 10.2.1.9-57sv |
sonicwall | sma_210_firmware | 𝑥 ≤ 10.2.1.9-57sv |
sonicwall | sma_400_firmware | 𝑥 ≤ 10.2.1.9-57sv |
sonicwall | sma_410_firmware | 𝑥 ≤ 10.2.1.9-57sv |
sonicwall | sma_500v_firmware | 𝑥 ≤ 10.2.1.9-57sv |
𝑥
= Vulnerable software versions
Common Weakness Enumeration