CVE-2020-5148
SonicWall Directory Services Connector vulnerability analysis and mitigation

SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls.


SourceNVD

Related SonicWall Directory Services Connector vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-5148HIGH8.2
  • SonicWall Directory Services Connector logoSonicWall Directory Services Connector
  • cpe:2.3:a:sonicwall:directory_services_connector
NoYesMar 05, 2021
CVE-2023-44219HIGH7.8
  • SonicWall Directory Services Connector logoSonicWall Directory Services Connector
  • cpe:2.3:a:sonicwall:directory_services_connector
NoYesOct 27, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management