An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.
This issue affects only firmware version SonicOS 7.1.1-7040.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 | Vendor Advisory |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 - Vendor Advisory |
14 Feb 2024, 21:46
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:sonicwall:nsv_870:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570p:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz370:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz470:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz370w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570w:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sonicos:7.1.1-7040:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_270:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz270w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:t2270:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_470:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz470w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz670:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
First Time |
Sonicwall
Sonicwall nsa 3700 Sonicwall tz470w Sonicwall nsv 870 Sonicwall nsa 6700 Sonicwall tz470 Sonicwall tz570p Sonicwall nsa 5700 Sonicwall nsv 270 Sonicwall tz270w Sonicwall tz570w Sonicwall nssp 10700 Sonicwall nsa 4700 Sonicwall nssp 13700 Sonicwall sonicos Sonicwall nsa 2700 Sonicwall tz570 Sonicwall t2270 Sonicwall tz670 Sonicwall nsv 470 Sonicwall tz370 Sonicwall nssp 11700 Sonicwall tz370w |
|
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 - Vendor Advisory | |
CWE | CWE-287 |
08 Feb 2024, 03:29
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-08 02:15
Updated : 2024-11-21 08:56
NVD link : CVE-2024-22394
Mitre link : CVE-2024-22394
CVE.ORG link : CVE-2024-22394
JSON object : View
Products Affected
sonicwall
- nsa_2700
- nssp_10700
- nsv_470
- tz370w
- t2270
- tz470
- nssp_11700
- nsv_270
- nsa_4700
- tz670
- tz370
- nsv_870
- tz570p
- tz270w
- sonicos
- tz570
- nsa_6700
- tz570w
- nssp_13700
- nsa_5700
- tz470w
- nsa_3700
CWE
CWE-287
Improper Authentication