SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Sonicwall Sma 100 | — | Upgrade SonicWall SMA-100 to the latest version | Nov 10, 2025 | Jan 7, 2025 |
| Sonicwall Sonicos | — | Update SonicWall SonicOS Gen7 to version 7.2.0-7015 or laterUpdate SonicWall SonicOS Gen7 to version 7.0.1-5169 or laterUpdate SonicWall SonicOS Gen8 to version 8.0.1-8017 or laterUpdate SonicWall SonicOS Gen6 to version 6.5.5.1-6n or laterUpdate SonicWall SonicOS Gen6 NSv to version 6.5.4.4-44v-21-2472 or later | May 25, 2026 | Jan 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub