Lucene search

K
cve[email protected]CVE-2023-1101
HistoryMar 02, 2023 - 10:15 p.m.

CVE-2023-1101

2023-03-0222:15:09
CWE-307
web.nvd.nist.gov
57
sonicos
sslvpn
cve-2023-1101
vulnerability
mfa
nvd

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.9%

SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.

Affected configurations

NVD
Node
sonicwallsonicosRange<7.0.1-5111
AND
sonicwallnsa_2700Match-
OR
sonicwallnsa_3700Match-
OR
sonicwallnsa_4700Match-
OR
sonicwallnsa_5700Match-
OR
sonicwallnsa_6700Match-
OR
sonicwallnssp_10700Match-
OR
sonicwallnssp_11700Match-
OR
sonicwallnssp_13700Match-
OR
sonicwallnsv_270Match-
OR
sonicwallnsv_470Match-
OR
sonicwallnsv_870Match-
OR
sonicwalltz270Match-
OR
sonicwalltz270wMatch-
OR
sonicwalltz370Match-
OR
sonicwalltz370wMatch-
OR
sonicwalltz470Match-
OR
sonicwalltz470wMatch-
OR
sonicwalltz570Match-
OR
sonicwalltz570pMatch-
OR
sonicwalltz570wMatch-
OR
sonicwalltz670Match-
Node
sonicwallsonicosRange7.0.1-5083
AND
sonicwallnssp_15700Match-
Node
sonicwallsonicosRange6.5.4.4-44v-21-1551
AND
sonicwallnsv_10Match-
OR
sonicwallnsv_100Match-
OR
sonicwallnsv_1600Match-
OR
sonicwallnsv_200Match-
OR
sonicwallnsv_25Match-
OR
sonicwallnsv_300Match-
OR
sonicwallnsv_400Match-
OR
sonicwallnsv_50Match-
OR
sonicwallnsv_800Match-
Node
sonicwallsonicosRange6.5.4.11-97n
AND
sonicwallnsa_2600Match-
OR
sonicwallnsa_2650Match-
OR
sonicwallnsa_3600Match-
OR
sonicwallnsa_3650Match-
OR
sonicwallnsa_4600Match-
OR
sonicwallnsa_4650Match-
OR
sonicwallnsa_5600Match-
OR
sonicwallnsa_5650Match-
OR
sonicwallnsa_6600Match-
OR
sonicwallnsa_6650Match-
OR
sonicwallnsa_9250Match-
OR
sonicwallnsa_9450Match-
OR
sonicwallnsa_9650Match-
OR
sonicwallnssp12400Match-
OR
sonicwallnssp12800Match-
OR
sonicwallsm10200Match-
OR
sonicwallsm10400Match-
OR
sonicwallsm10800Match-
OR
sonicwallsm9200Match-
OR
sonicwallsm9400Match-
OR
sonicwallsm9600Match-
OR
sonicwallsm9800Match-
OR
sonicwallsoho_250Match-
OR
sonicwallsoho_250wMatch-
OR
sonicwallsohowMatch-
OR
sonicwalltz300Match-
OR
sonicwalltz300pMatch-
OR
sonicwalltz300wMatch-
OR
sonicwalltz350Match-
OR
sonicwalltz350wMatch-
OR
sonicwalltz400Match-
OR
sonicwalltz400wMatch-
OR
sonicwalltz500Match-
OR
sonicwalltz500wMatch-
OR
sonicwalltz600Match-
OR
sonicwalltz600pMatch-

CNA Affected

[
  {
    "vendor": "SonicWall",
    "product": "SonicOS",
    "versions": [
      {
        "version": "SonicOS 6.5.4.11-97n and earlier",
        "status": "affected"
      },
      {
        "version": "SonicOS NSv 6.5.4.4-44v-21-1551 and earlier",
        "status": "affected"
      },
      {
        "version": "SonicOS NSsp 7.0.1-5083 and earlier",
        "status": "affected"
      },
      {
        "version": "SonicOS 7.0.1-5095 and earlier",
        "status": "affected"
      }
    ]
  }
]

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.9%

Related for CVE-2023-1101