PT-2024-19387 · Unknown · Sma100 Ssl-Vpn

Published

2024-02-23

·

Updated

2024-12-05

·

CVE-2024-22395

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SMA100 SSL-VPN virtual office portal (affected versions not specified)
Description An improper access control issue has been identified in the SMA100 SSL-VPN virtual office portal. This issue could potentially enable a remote authenticated attacker to associate another user's MFA mobile application under specific conditions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-22395

Affected Products

Sma100 Ssl-Vpn