vulnerability
SonicWall SMA-100: CVE-2024-12802: SSL-VPN MFA Bypass Due to UPN and SAM Account Handling in Microsoft AD
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:L/Au:N/C:C/I:C/A:N) | Jan 7, 2025 | Nov 10, 2025 | Nov 10, 2025 |
Severity
9
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:N)
Published
Jan 7, 2025
Added
Nov 10, 2025
Modified
Nov 10, 2025
Description
SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.
Solution
sonicwall-sma-100-upgrade-10_2_1_14-75
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.