CVE-2024-22394

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sonicwall:sonicos:7.1.1-7040:*:*:*:*:*:*:*
OR cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv_270:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv_470:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv_870:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:t2270:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz270w:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz370:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz370w:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz470:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz470w:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz570:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz570p:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz570w:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz670:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:56

Type Values Removed Values Added
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 - Vendor Advisory () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 - Vendor Advisory

14 Feb 2024, 21:46

Type Values Removed Values Added
First Time Sonicwall nsa 5700
Sonicwall tz370w
Sonicwall nsa 2700
Sonicwall nsa 3700
Sonicwall tz270w
Sonicwall nsa 4700
Sonicwall nsv 470
Sonicwall nsv 870
Sonicwall tz570w
Sonicwall nsa 6700
Sonicwall t2270
Sonicwall sonicos
Sonicwall tz470
Sonicwall
Sonicwall nsv 270
Sonicwall nssp 11700
Sonicwall nssp 13700
Sonicwall tz470w
Sonicwall nssp 10700
Sonicwall tz570p
Sonicwall tz370
Sonicwall tz570
Sonicwall tz670
CPE cpe:2.3:h:sonicwall:tz570w:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sonicos:7.1.1-7040:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz570p:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:t2270:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz670:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz270w:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz470:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz470w:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz370:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv_870:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz570:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv_270:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:tz370w:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:nsv_470:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0003 - Vendor Advisory

08 Feb 2024, 03:29

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-08 02:15

Updated : 2024-11-21 08:56


NVD link : CVE-2024-22394

Mitre link : CVE-2024-22394

CVE.ORG link : CVE-2024-22394


JSON object : View

Products Affected

sonicwall

  • nsa_6700
  • nsa_3700
  • nssp_11700
  • nsa_4700
  • nsv_870
  • tz470
  • tz370w
  • t2270
  • tz570
  • nssp_13700
  • nssp_10700
  • tz270w
  • tz570p
  • tz470w
  • sonicos
  • nsa_5700
  • tz570w
  • nsa_2700
  • tz670
  • tz370
  • nsv_470
  • nsv_270
CWE
CWE-287

Improper Authentication