CVE Vulnerabilities

CVE-2020-5148

Improper Authentication

Published: Mar 05, 2021 | Modified: Mar 15, 2021
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

SonicWall SSO-agent default configuration uses NetAPI to probe the associated IPs in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Directory_services_connector Sonicwall * 4.1.19 (excluding)

Potential Mitigations

References