← לוח פגיעויות

CVE-2024-53704

קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
95% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-287

מוצרים מושפעים

sonicwall: sonicos; sonicwall: nsa 2700; sonicwall: nsa 3700; sonicwall: nsa 4700; sonicwall: nsa 5700; sonicwall: nsa 6700; sonicwall: nssp 10700; sonicwall: nssp 11700; sonicwall: nssp 13700; sonicwall: nssp 15700; sonicwall: nsv 270; sonicwall: nsv 470; sonicwall: nsv 870; sonicwall: tz270; sonicwall: tz270w

קישורים