CVE-2023-5970

Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain...

Basic Information

CVE State
PUBLISHED
Reserved Date
November 06, 2023
Published Date
December 05, 2023
Last Updated
August 02, 2024
Vendor
SonicWall
Product
SMA100
Description
Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploit Status

Exploited in the Wild
Yes (2025-10-26 22:33:03 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-10-26 22:33:03 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel