Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cm74-jg3x-hghv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

EPSS

Процентиль: 39%
0.00174
Низкий

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerability. When the users publicly display their organization’s internal domain names in the SSL-VPN authentication page, an attacker with knowledge of internal domain names can potentially take advantage of this vulnerability.

EPSS

Процентиль: 39%
0.00174
Низкий