First published: Fri Mar 25 2022(Updated: )
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall SonicOS | <=7.0.1-5050 | |
Sonicwall Nsa 2700 | ||
Sonicwall Nsa 3700 | ||
Sonicwall Nsa 4700 | ||
Sonicwall Nsa 5700 | ||
Sonicwall Nsa 6700 | ||
Sonicwall Nssp 10700 | ||
Sonicwall Nssp 11700 | ||
Sonicwall Nssp 13700 | ||
Sonicwall Nsv 270 | ||
Sonicwall Nsv 470 | ||
Sonicwall Nsv 870 | ||
Sonicwall Tz270 | ||
Sonicwall Tz270w | ||
Sonicwall Tz370 | ||
Sonicwall Tz370w | ||
Sonicwall Tz470 | ||
Sonicwall Tz470w | ||
Sonicwall Tz570 | ||
Sonicwall Tz570p | ||
Sonicwall Tz570w | ||
Sonicwall Tz670 | ||
SonicWall SonicOS | <=7.0.1-r579 | |
Sonicwall Nssp 15700 | ||
Sonicwall Sonicosv | <=6.5.4.4-44v-21-1452 | |
Sonicwall Nsv 10 | ||
Sonicwall Nsv 100 | ||
Sonicwall Nsv 1600 | ||
Sonicwall Nsv 200 | ||
Sonicwall Nsv 25 | ||
Sonicwall Nsv 300 | ||
Sonicwall Nsv 400 | ||
Sonicwall Nsv 50 | ||
Sonicwall Nsv 800 | ||
SonicWall next-generation firewall (NGFW) | =series 6 | |
SonicWall next-generation firewall (NGFW) | =series 7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22274 is a Stack-based buffer overflow vulnerability in the SonicOS firewall that allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially execute arbitrary code.
CVE-2022-22274 has a severity level of 9.8 (Critical).
As a cybersecurity analyst, I cannot provide guidance on how to exploit vulnerabilities. It is important to patch the affected software as soon as possible to mitigate the risk.
To fix CVE-2022-22274, it is recommended to apply the necessary security patches provided by SonicWall. Check the SonicWall website or contact their support for specific instructions.
You can find more information about CVE-2022-22274 on the SonicWall PSIRT website at the following link: [SonicWall PSIRT - CVE-2022-22274](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003)