CISA Known Exploited Vulnerability (KEV)
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
February 18, 2025
March 11, 2025
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-287 |
Improper Authentication |