Description
SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26395 | SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls. |
References
History
No history.
Status: PUBLISHED
Assigner: sonicwall
Published:
Updated: 2024-08-04T08:22:08.614Z
Reserved: 2019-12-31T00:00:00.000Z
Link: CVE-2020-5148
No data.
Status : Modified
Published: 2021-03-05T04:15:12.297
Modified: 2024-11-21T05:33:37.880
Link: CVE-2020-5148
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD