CVE-2024-53704

CRITICAL(9.8)KEVRansomwareWahrscheinlich ausgenutzt

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

Beschreibung

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

KEV-Informationen

Hersteller
SonicWall
Produkt
SonicOS
Hinzugefügt am
18. Februar 2025
Fälligkeitsdatum
11. März 2025
Erforderliche Maßnahme
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
3.9
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
sonicwallsonicos>= 7.1.1-7040, <= 7.1.1-7058; 7.1.2-7019; 8.0.0-8035

Mehrere CVSS-Bewertungen

Quelle: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.2
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Referenzen

CVSS-Score

9.8
CRITICAL(9.8)

EPSS-Score

EPSS-Score95.13%
EPSS-Perzentil99.9%

Daten

Veröffentlicht9. Januar 2025
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.