SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen6 to version 6.5.4.12-101n or laterUpdate SonicWall SonicOS Gen7 to version 7.0.1-5111 or laterUpdate SonicWall SonicOS Gen6 NSv to version 6.5.4.4-44v-21-2079 or later | May 25, 2026 | Mar 2, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub