← Back to CVE List
Vulnerability Intelligence Report

CVE-2023-5970

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:0.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-287 ↗CWE-287 Improper Authentication

Affected Products & Versions

Vendor Product Affected Versions
SonicWall SMA100 10.2.1.9-57sv and earlier versions (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.911%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySonicWall, Inc. · Vendor · USA
Reserved2023-11-06T17:14:04
Published2023-12-05T20:20:01
Patch Date2023-12-05
Last Updated2024-08-02T08:14:25

LINK COPIED TO CLIPBOARD