CVE CVE

CVE-2024-53704

CISA Known Exploited Vulnerability (KEV)

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

February 18, 2025

March 11, 2025

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Weakness Enumeration

CWE-ID CWE Name

CWE-287
Improper Authentication

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
8.2
Severity:

HIGH

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

CVSS v2

Not defined