SonicWall SMA1000
cpe:2.3:h:sonicwall:sma1000:*:*:*:*:*:*:*, +1 more
- <= 12.4.3-03245
- <= 12.5.0-02283
A vulnerability allowing remote authenticated SSLVPN users to bypass Workplace or Connect Tunnel TOTP authentication has been identified in SonicWall SMA1000 series appliances. This issue arises from improper handling of Unicode encoding, affecting versions 12.4.3-03245 and earlier, as well as 12.5.0-02283 and earlier.
Exploitation of this vulnerability allows for bypassing TOTP authentication, potentially leading to unauthorized access to resources or functionalities that require TOTP verification.
Users are advised to upgrade to SonicWall SMA1000 series versions 12.4.3-03387 or 12.5.0-02624 or higher. The latest platform-hotfix is available for download on mysonicwall.com.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.