8.8

CVE-2023-5970

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.

Data is provided by the National Vulnerability Database (NVD)
SonicwallSma 200 Firmware Version <= 10.2.1.9-57sv
   SonicwallSma 200 Version-
SonicwallSma 210 Firmware Version <= 10.2.1.9-57sv
   SonicwallSma 210 Version-
SonicwallSma 400 Firmware Version <= 10.2.1.9-57sv
   SonicwallSma 400 Version-
SonicwallSma 410 Firmware Version <= 10.2.1.9-57sv
   SonicwallSma 410 Version-
SonicwallSma 500v Firmware Version <= 10.2.1.9-57sv
   SonicwallSma 500v Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.57% 0.676
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.