Loading HuntDB...

GHSA-ff32-cmvq-x6c5

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling attackers to bypass MFA by exploiting the alternative account name.

Related CVEs

Key Information

GHSA ID
GHSA-ff32-cmvq-x6c5
Published
January 9, 2025 9:31 AM
Last Modified
January 9, 2025 3:31 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.