vulnerability

SonicWall SMA-100: CVE-2024-12802: SSL-VPN MFA Bypass Due to UPN and SAM Account Handling in Microsoft AD

Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
Jan 7, 2025
Added
Nov 10, 2025
Modified
Nov 10, 2025

Description

SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.

Solution

sonicwall-sma-100-upgrade-10_2_1_14-75
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.