CVE-2024-22395

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

History

05 Dec 2024, 17:04

Type Values Removed Values Added
First Time Sonicwall sma 410 Firmware
Sonicwall sma 210 Firmware
Sonicwall sma 200 Firmware
Sonicwall sma 500v
Sonicwall sma 200
Sonicwall
Sonicwall sma 400 Firmware
Sonicwall sma 500v Firmware
Sonicwall sma 400
Sonicwall sma 210
Sonicwall sma 410
CPE cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0001 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0001 - Vendor Advisory
CWE NVD-CWE-noinfo

21 Nov 2024, 08:56

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad de control de acceso inadecuado en el portal de oficina virtual SMA100 SSL-VPN, que en condiciones específicas podría permitir que un atacante autenticado remoto asocie la aplicación móvil MFA de otro usuario.
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0001 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0001 -

24 Feb 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-24 00:15

Updated : 2024-12-05 17:04


NVD link : CVE-2024-22395

Mitre link : CVE-2024-22395

CVE.ORG link : CVE-2024-22395


JSON object : View

Products Affected

sonicwall

  • sma_200_firmware
  • sma_400
  • sma_200
  • sma_410_firmware
  • sma_210_firmware
  • sma_500v_firmware
  • sma_410
  • sma_210
  • sma_500v
  • sma_400_firmware
CWE
CWE-287

Improper Authentication

NVD-CWE-noinfo