Improper access control in SonicWall products - CVE-2022-22282

 

Improper access control in SonicWall products - CVE-2022-22282

Published: May 17, 2022


Vulnerability identifier: #VU63302
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22282
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote non-authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

SonicWall SMA 1000
SonicWall SMA 6200
SonicWall SMA 6210
SonicWall SMA 7200
SonicWall SMA 7210
SonicWall SMA 8000v

How to mitigate CVE-2022-22282

Install updates from vendor's website.

SonicWall SMA 1000 - update to 12.4.1-02994
SonicWall SMA 6200 - update to 12.4.1-02994
SonicWall SMA 6210 - update to 12.4.1-02994
SonicWall SMA 7200 - update to 12.4.1-02994
SonicWall SMA 7210 - update to 12.4.1-02994
SonicWall SMA 8000v - update to 12.4.1-02994

External References

Related Security Bulletins