Improper Restriction of Excessive MFA Attempts in SonicOS by SonicWall
CVE-2023-1101
8.8HIGH
What is CVE-2023-1101?
The SonicWall SonicOS SSLVPN is affected by a vulnerability that permits an authenticated attacker to bypass limitations on the number of Multi-Factor Authentication (MFA) attempts. This permissiveness could potentially be exploited, allowing attackers to leverage excessive MFA codes to gain unauthorized access. Properly managing MFA attempts is critical to maintaining the integrity of the authentication process.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SonicOS SonicOS 6.5.4.11-97n and earlier
SonicOS SonicOS NSv 6.5.4.4-44v-21-1551 and earlier
SonicOS SonicOS NSsp 7.0.1-5083 and earlier
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved