Allocation of Resources Without Limits or Throttling in SonicOS - CVE-2022-22278
Published: April 27, 2022
SonicOS
SonicWall
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to CFS (Content filtering service) in SonicOS returns a large 403 forbidden
HTTP response message to the source address when users try to access
resources prohibited by CFS feature. A remote attacker can send multiple requests to the system that trigger 403 error and consume all available bandwidth.