CVE-2024-22395: Medium severity SonicWall Sma 200 Firmware vulnerability
Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22395?
CVE-2024-22395 has been assessed as a medium severity vulnerability due to improper access control leading to potential multi-factor authentication (MFA) association issues.
How do I fix CVE-2024-22395?
To mitigate CVE-2024-22395, upgrade your SonicWall SMA firmware to version 10.2.1.11-65sv or later.
Which devices are affected by CVE-2024-22395?
CVE-2024-22395 affects SonicWall SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v firmware versions prior to 10.2.1.11-65sv.
Can CVE-2024-22395 be exploited remotely?
Yes, CVE-2024-22395 may allow a remote authenticated attacker to exploit the vulnerability under certain conditions.
What are the implications of CVE-2024-22395?
The implications of CVE-2024-22395 include unauthorized access to another user's MFA application, which could lead to compromised accounts.