Improper access control in SonicWall products - CVE-2022-22282
Published: May 17, 2022
Vulnerability identifier: #VU63302
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22282
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote non-authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application.
Affected software
SonicWall SMA 1000
SonicWall SMA 6200
SonicWall SMA 6210
SonicWall SMA 7200
SonicWall SMA 7210
SonicWall SMA 8000v
SonicWall SMA 6200
SonicWall SMA 6210
SonicWall SMA 7200
SonicWall SMA 7210
SonicWall SMA 8000v
How to mitigate CVE-2022-22282
Install updates from vendor's website.
SonicWall SMA 1000 - update to 12.4.1-02994
SonicWall SMA 6200 - update to 12.4.1-02994
SonicWall SMA 6210 - update to 12.4.1-02994
SonicWall SMA 7200 - update to 12.4.1-02994
SonicWall SMA 7210 - update to 12.4.1-02994
SonicWall SMA 8000v - update to 12.4.1-02994
SonicWall SMA 6200 - update to 12.4.1-02994
SonicWall SMA 6210 - update to 12.4.1-02994
SonicWall SMA 7200 - update to 12.4.1-02994
SonicWall SMA 7210 - update to 12.4.1-02994
SonicWall SMA 8000v - update to 12.4.1-02994