Improper Privilege Management in SonicWall SonicOS SSL VPN Tunnel
CVE-2023-41715

8.8HIGH

Key Information:

Vendor
SonicWall
Status
Vendor
CVE Published:
17 October 2023

Summary

The vulnerability in SonicWall SonicOS SSL VPN Tunnel allows authenticated users to elevate their privileges, potentially leading to unauthorized access to sensitive data and system functionalities within the secured environment. This flaw raises significant concerns regarding user security and the integrity of access controls in the VPN. Organizations using SonicWall's solutions should assess their systems for this vulnerability and apply best security practices to mitigate potential risks.

Affected Version(s)

SonicOS 7.0.1-5119 and earlier versions

SonicOS 7.0.1-5129 and earlier versions

SonicOS 6.5.4.4-44v-21-2079 and earlier versions

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.