Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker to associate another user's MFA mobile application.
| Software | From | Fixed in |
|---|---|---|
| sonicwall / sma_200_firmware | - | 10.2.1.11-65sv |
| sonicwall / sma_210_firmware | - | 10.2.1.11-65sv |
| sonicwall / sma_400_firmware | - | 10.2.1.11-65sv |
| sonicwall / sma_410_firmware | - | 10.2.1.11-65sv |
| sonicwall / sma_500v_firmware | - | 10.2.1.11-65sv |