CVE-2024-22395

MEDIUM

SonicWall SMA 200/210/400/410/500v < 10.2.1.11-65sv Authenticated MFA Bypass

Title source: llm
STIX 2.1

Description

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.

References (1)

Core 1
Core References

Scores

CVSS v3 6.3
EPSS 0.0049
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (5)
sonicwall/sma_200_firmware < 10.2.1.11-65sv
sonicwall/sma_210_firmware < 10.2.1.11-65sv
sonicwall/sma_400_firmware < 10.2.1.11-65sv
sonicwall/sma_410_firmware < 10.2.1.11-65sv
sonicwall/sma_500v_firmware < 10.2.1.11-65sv
Published Feb 24, 2024
Tracked Since Feb 18, 2026