SonicWall SSO-agent default configuration uses NetAPI to probe the associated IPs in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Directory_services_connector | Sonicwall | * | 4.1.19 (excluding) |