SonicWall SMA1000
cpe:2.3:h:sonicwall:sma1000:*:*:*:*:*:*:*, +1 more
- <= 12.4.3-03245
- <= 12.5.0-02283
A vulnerability in SonicWall SMA1000 series appliances, specifically in versions 12.4.3-03245 and earlier, as well as 12.5.0-02283 and earlier, has been identified. This vulnerability arises from improper handling of Unicode encoding, which enables a remote authenticated SSLVPN administrator to bypass AMC TOTP authentication. Notably, this issue does not affect SSL-VPN on SonicWall firewall products.
Exploitation of this vulnerability allows for bypassing TOTP authentication, potentially leading to unauthorized access or actions that require TOTP verification.
Users are advised to upgrade to SonicWall SMA1000 versions 12.4.3-03387 (platform-hotfix) or 12.5.0-02624 (platform-hotfix). The latest platform-hotfix can be downloaded from mysonicwall.com.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.