8.8

CVE-2023-41715

SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SonicwallSonicos Version < 7.0.1-5145
   SonicwallNsa2700 Version-
   SonicwallNsa3700 Version-
   SonicwallNsa4700 Version-
   SonicwallNsa5700 Version-
   SonicwallNsa6700 Version-
   SonicwallNssp10700 Version-
   SonicwallNssp11700 Version-
   SonicwallNssp13700 Version-
   SonicwallNssp15700 Version-
   SonicwallNsv10 Version-
   SonicwallNsv100 Version-
   SonicwallNsv1600 Version-
   SonicwallNsv200 Version-
   SonicwallNsv25 Version-
   SonicwallNsv270 Version-
   SonicwallNsv300 Version-
   SonicwallNsv400 Version-
   SonicwallNsv470 Version-
   SonicwallNsv50 Version-
   SonicwallNsv800 Version-
   SonicwallNsv870 Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz670 Version-
SonicwallSonicos Version < 6.5.4.4-44v-21-2340
   SonicwallNsv10 Version-
   SonicwallNsv100 Version-
   SonicwallNsv1600 Version-
   SonicwallNsv200 Version-
   SonicwallNsv25 Version-
   SonicwallNsv270 Version-
   SonicwallNsv300 Version-
   SonicwallNsv400 Version-
   SonicwallNsv470 Version-
   SonicwallNsv50 Version-
   SonicwallNsv800 Version-
   SonicwallNsv870 Version-
SonicwallSonicos Version < 6.5.4.13-105n
   SonicwallNsa 2600 Version-
   SonicwallNsa 2650 Version-
   SonicwallNsa 3600 Version-
   SonicwallNsa 3650 Version-
   SonicwallNsa 4600 Version-
   SonicwallNsa 4650 Version-
   SonicwallNsa 5600 Version-
   SonicwallNsa 5650 Version-
   SonicwallNsa 6600 Version-
   SonicwallNsa 6650 Version-
   SonicwallSm 9200 Version-
   SonicwallSm 9250 Version-
   SonicwallSm 9400 Version-
   SonicwallSm 9450 Version-
   SonicwallSm 9600 Version-
   SonicwallSm 9650 Version-
   SonicwallSoho 250 Version-
   SonicwallSoho 250w Version-
   SonicwallSohow Version-
   SonicwallTz 300 Version-
   SonicwallTz 300p Version-
   SonicwallTz 300w Version-
   SonicwallTz 350 Version-
   SonicwallTz 400 Version-
   SonicwallTz 400w Version-
   SonicwallTz 500 Version-
   SonicwallTz 500w Version-
   SonicwallTz 600 Version-
   SonicwallTz 600p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.562
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.