8.8

CVE-2023-41715

SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.

Data is provided by the National Vulnerability Database (NVD)
SonicwallSonicos Version < 7.0.1-5145
   SonicwallNsa2700 Version-
   SonicwallNsa3700 Version-
   SonicwallNsa4700 Version-
   SonicwallNsa5700 Version-
   SonicwallNsa6700 Version-
   SonicwallNssp10700 Version-
   SonicwallNssp11700 Version-
   SonicwallNssp13700 Version-
   SonicwallNssp15700 Version-
   SonicwallNsv10 Version-
   SonicwallNsv100 Version-
   SonicwallNsv1600 Version-
   SonicwallNsv200 Version-
   SonicwallNsv25 Version-
   SonicwallNsv270 Version-
   SonicwallNsv300 Version-
   SonicwallNsv400 Version-
   SonicwallNsv470 Version-
   SonicwallNsv50 Version-
   SonicwallNsv800 Version-
   SonicwallNsv870 Version-
   SonicwallTz270 Version-
   SonicwallTz270w Version-
   SonicwallTz370 Version-
   SonicwallTz370w Version-
   SonicwallTz470 Version-
   SonicwallTz470w Version-
   SonicwallTz570 Version-
   SonicwallTz570p Version-
   SonicwallTz570w Version-
   SonicwallTz670 Version-
SonicwallSonicos Version < 6.5.4.4-44v-21-2340
   SonicwallNsv10 Version-
   SonicwallNsv100 Version-
   SonicwallNsv1600 Version-
   SonicwallNsv200 Version-
   SonicwallNsv25 Version-
   SonicwallNsv270 Version-
   SonicwallNsv300 Version-
   SonicwallNsv400 Version-
   SonicwallNsv470 Version-
   SonicwallNsv50 Version-
   SonicwallNsv800 Version-
   SonicwallNsv870 Version-
SonicwallSonicos Version < 6.5.4.13-105n
   SonicwallNsa 2600 Version-
   SonicwallNsa 2650 Version-
   SonicwallNsa 3600 Version-
   SonicwallNsa 3650 Version-
   SonicwallNsa 4600 Version-
   SonicwallNsa 4650 Version-
   SonicwallNsa 5600 Version-
   SonicwallNsa 5650 Version-
   SonicwallNsa 6600 Version-
   SonicwallNsa 6650 Version-
   SonicwallSm 9200 Version-
   SonicwallSm 9250 Version-
   SonicwallSm 9400 Version-
   SonicwallSm 9450 Version-
   SonicwallSm 9600 Version-
   SonicwallSm 9650 Version-
   SonicwallSoho 250 Version-
   SonicwallSoho 250w Version-
   SonicwallSohow Version-
   SonicwallTz 300 Version-
   SonicwallTz 300p Version-
   SonicwallTz 300w Version-
   SonicwallTz 350 Version-
   SonicwallTz 400 Version-
   SonicwallTz 400w Version-
   SonicwallTz 500 Version-
   SonicwallTz 500w Version-
   SonicwallTz 600 Version-
   SonicwallTz 600p Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.562
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.