SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0012 | Vendor Advisory |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0012 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
History
No history.
Information
Published : 2023-10-17 23:15
Updated : 2025-05-02 19:15
NVD link : CVE-2023-41715
Mitre link : CVE-2023-41715
CVE.ORG link : CVE-2023-41715
JSON object : View
Products Affected
sonicwall
- sm_9450
- tz_400w
- nsv470
- nsv870
- tz670
- tz_500
- nsa2700
- nsv25
- nsv270
- nsv800
- nsa_2650
- nssp10700
- nsv400
- nsa4700
- tz_300w
- nsa_3600
- tz_500w
- nsv300
- tz470w
- tz370w
- tz_300
- nssp13700
- nsa_5600
- nsv50
- nssp11700
- sm_9600
- nsa_6600
- nsa_4650
- nsv10
- sm_9400
- sm_9250
- tz_300p
- nsa6700
- nsa3700
- tz570p
- sm_9200
- tz_350
- tz370
- tz570
- nssp15700
- tz_600
- tz_600p
- nsa_3650
- nsa_4600
- nsv1600
- tz270
- nsa_5650
- nsa_6650
- sm_9650
- nsa5700
- soho_250
- nsv100
- nsa_2600
- sohow
- tz_400
- nsv200
- tz570w
- soho_250w
- sonicos
- tz470
- tz270w
CWE
CWE-269
Improper Privilege Management