High severity8.8NVD Advisory· Published Dec 5, 2023· Updated Jun 17, 2026
CVE-2023-5970
CVE-2023-5970
Description
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.
Affected products
7- cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
Patches
Vulnerability mechanics
References
1- psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018nvdVendor Advisory
News mentions
0No linked articles in our index yet.