SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
References
| Link | Resource |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0005 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0005 | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
History
21 Nov 2024, 07:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0005 - Vendor Advisory |
14 Mar 2023, 16:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:sonicwall:tz300:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_25:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_3650:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_3600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz370w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sm9800:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz400w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_470:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_1600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz350w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_50:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_5650:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_200:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:soho_250w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sm9400:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz300p:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_870:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz670:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_10:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz470w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz270w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_2650:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_100:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz350:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570p:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_15700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz300w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz400:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sm9600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sohow:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:soho_250:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp12800:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sm9200:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_9250:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_800:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp12400:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz500w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_2600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_400:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_4650:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_6600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_6650:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_9450:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sm10400:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_5600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sm10200:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz370:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_9650:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz500:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz470:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_270:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sm10800:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv_300:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_4600:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz600p:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz270:-:*:*:*:*:*:*:* |
|
| CWE | CWE-307 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| References | (CONFIRM) https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0005 - Vendor Advisory |
02 Mar 2023, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-03-02 22:15
Updated : 2025-03-07 20:15
NVD link : CVE-2023-1101
Mitre link : CVE-2023-1101
CVE.ORG link : CVE-2023-1101
JSON object : View
Products Affected
sonicwall
- sm9600
- nsv_25
- nsa_4600
- nsa_2650
- tz600p
- nsa_3700
- nssp12400
- nsv_870
- tz470
- nsv_50
- tz300
- nsv_270
- nssp_13700
- nsa_3600
- tz570
- nsa_9450
- nsa_4650
- soho_250w
- nsv_1600
- nsa_5650
- tz300w
- sm10200
- tz500w
- nsa_6600
- nsa_3650
- sonicos
- tz270
- nsa_9250
- nssp_11700
- nsa_6650
- nsa_5700
- nsv_470
- tz370
- tz570w
- nsv_200
- sm9400
- nsa_2600
- nssp12800
- tz400w
- nssp_10700
- tz500
- nssp_15700
- nsv_10
- nsa_4700
- nsa_6700
- nsv_400
- nsa_9650
- tz300p
- tz470w
- nsa_5600
- tz400
- tz570p
- nsv_100
- tz670
- nsv_300
- sm10800
- sm9800
- nsa_2700
- nsv_800
- sm10400
- sohow
- tz370w
- sm9200
- tz350
- tz600
- tz270w
- tz350w
- soho_250
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
