Use of Hard-coded Cryptographic Key in SonicWall products - CVE-2022-1701
Published: May 17, 2022
Vulnerability identifier: #VU63313
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-1701
CWE-ID: CWE-321
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
SonicWall SMA 1000
SonicWall SMA 6200
SonicWall SMA 6210
SonicWall SMA 7200
SonicWall SMA 7210
SonicWall SMA 8000v
SonicWall SMA 1000
SonicWall SMA 6200
SonicWall SMA 6210
SonicWall SMA 7200
SonicWall SMA 7210
SonicWall SMA 8000v
Software vendor:
SonicWall
SonicWall
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to usage of a shared hard-coded encryption key. A local user who can obtain the key can gain access and manipulate sensitive information.
Remediation
Install updates from vendor's website.