SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: sonicwall

Published: 2021-03-05T03:45:14

Updated: 2021-03-05T03:45:14

Reserved: 2019-12-31T00:00:00


Link: CVE-2020-5148

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-03-05T04:15:12.297

Modified: 2021-03-15T17:06:00.347


Link: CVE-2020-5148

JSON object: View

cve-icon Redhat Information

No data.

CWE