Medium severity6.3NVD Advisory· Published Feb 24, 2024· Updated Jun 17, 2026
CVE-2024-22395
CVE-2024-22395
Description
Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
Affected products
7- cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.11-65sv
- cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.11-65sv
- cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.11-65sv
- cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.11-65sv
- cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*Range: <10.2.1.11-65sv
Patches
Vulnerability mechanics
References
1- psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0001nvdVendor Advisory
News mentions
0No linked articles in our index yet.