Use of Hard-coded Cryptographic Key in SonicWall products - CVE-2022-1701

 

Use of Hard-coded Cryptographic Key in SonicWall products - CVE-2022-1701

Published: May 17, 2022


Vulnerability identifier: #VU63313
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1701
CWE-ID: CWE-321
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to usage of a shared hard-coded encryption key. A local user who can obtain the key can gain access and manipulate sensitive information.


Affected software

SonicWall SMA 1000
SonicWall SMA 6200
SonicWall SMA 6210
SonicWall SMA 7200
SonicWall SMA 7210
SonicWall SMA 8000v

How to mitigate CVE-2022-1701

Install updates from vendor's website.

SonicWall SMA 1000 - update to 12.4.1-02994
SonicWall SMA 6200 - update to 12.4.1-02994
SonicWall SMA 6210 - update to 12.4.1-02994
SonicWall SMA 7200 - update to 12.4.1-02994
SonicWall SMA 7210 - update to 12.4.1-02994
SonicWall SMA 8000v - update to 12.4.1-02994

External References

Related Security Bulletins