8.8

CVE-2023-1101

SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SonicwallSonicos Version < 7.0.1-5111
   SonicwallNsa 2700 Version-
   SonicwallNsa 3700 Version-
   SonicwallNsa 4700 Version-
   SonicwallNsa 5700 Version-
   SonicwallNsa 6700 Version-
   SonicwallNssp 10700 Version-
   SonicwallNssp 11700 Version-
   SonicwallNssp 13700 Version-
   SonicwallNsv 270 Version-
   SonicwallNsv 470 Version-
   SonicwallNsv 870 Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz670 Version-
SonicwallSonicos Version <= 7.0.1-5083
   SonicwallNssp 15700 Version-
SonicwallSonicos Version <= 6.5.4.4-44v-21-1551
   SonicwallNsv 10 Version-
   SonicwallNsv 100 Version-
   SonicwallNsv 1600 Version-
   SonicwallNsv 200 Version-
   SonicwallNsv 25 Version-
   SonicwallNsv 300 Version-
   SonicwallNsv 400 Version-
   SonicwallNsv 50 Version-
   SonicwallNsv 800 Version-
SonicwallSonicos Version <= 6.5.4.11-97n
   SonicwallNsa 2600 Version-
   SonicwallNsa 2650 Version-
   SonicwallNsa 3600 Version-
   SonicwallNsa 3650 Version-
   SonicwallNsa 4600 Version-
   SonicwallNsa 4650 Version-
   SonicwallNsa 5600 Version-
   SonicwallNsa 5650 Version-
   SonicwallNsa 6600 Version-
   SonicwallNsa 6650 Version-
   SonicwallNsa 9250 Version-
   SonicwallNsa 9450 Version-
   SonicwallNsa 9650 Version-
   SonicwallNssp12400 Version-
   SonicwallNssp12800 Version-
   SonicwallSm10200 Version-
   SonicwallSm10400 Version-
   SonicwallSm10800 Version-
   SonicwallSm9200 Version-
   SonicwallSm9400 Version-
   SonicwallSm9600 Version-
   SonicwallSm9800 Version-
   SonicwallSoho 250 Version-
   SonicwallSoho 250w Version-
   SonicwallSohow Version-
   SonicwallTz300 Version-
   SonicwallTz300p Version-
   SonicwallTz300w Version-
   SonicwallTz350 Version-
   SonicwallTz350w Version-
   SonicwallTz400 Version-
   SonicwallTz400w Version-
   SonicwallTz500 Version-
   SonicwallTz500w Version-
   SonicwallTz600 Version-
   SonicwallTz600p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.544
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-307 Improper Restriction of Excessive Authentication Attempts

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.