CVE-2024-12802
CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40º percentile).
Vulnerabilità · 132 giorni fa
L’assunzione errata è che un firmware update significhi che la VPN sia sicura. Sugli appliance SonicWall Gen6 SSL-VPN, non è così: i dispositivi possono risultare patched e lasciare comunque MFA aggirabile finché il server LDAP non viene riconfigurato manualmente.
CVSS 9.1 CRITICAL: sSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User… EPSS 0.5% (40º percentile).
2 fonti che coprono questa storia
Hackers bypass SonicWall VPN MFA due to incomplete patching
Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransomware attacks.
Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN
Researchers said a wave of attacks began in February targeting firewalls that appeared to be protected.
Riepilogo fornitore: SonicWall
Part of the PlainSec briefing for 2026-05-21