CVE-2024-12802 – SonicWALL SSL-VPN Active Directory MFA Bypass

The following table lists the changes that have been made to the
CVE-2024-12802 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 09, 2025

    Action Type Old Value New Value
    Added Description SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.
    Added CWE CWE-305
    Added Reference https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001
Share the Post:

Related Posts