First published: Fri Mar 25 2022(Updated: )
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall Next-Generation Firewall | =series 6 | |
SonicWall Next-Generation Firewall | =series 7 | |
SonicWall SonicOS | <=7.0.1-5050 | |
SonicWall NSA 2700 | ||
SonicWall NSA 3700 Firmware | ||
SonicWall NSA 4700 | ||
SonicWall NSA 5700 | ||
SonicWall NSA 6700 Firmware | ||
SonicWall NSSP 10700 Firmware | ||
SonicWall NSSP 11700 | ||
SonicWall NSSP 13700 | ||
SonicWall NSV 270 | ||
SonicWall NSV 470 Firmware | ||
SonicWall NSv 870 | ||
SonicWall TZ270 | ||
SonicWall TZ270W Firmware | ||
SonicWall TZ370 | ||
SonicWall TZ370W Firmware | ||
SonicWall TZ470 Firmware | ||
SonicWall TZ470W Firmware | ||
SonicWall TZ570 Firmware | ||
SonicWall TZ570P Firmware | ||
SonicWall TZ570W Firmware | ||
SonicWall TZ670 Firmware | ||
SonicWall SonicOS | <=7.0.1-r579 | |
SonicWall NSSP 15700 | ||
SonicWall SonicOS | <=6.5.4.4-44v-21-1452 | |
SonicWall NSV 10 Firmware | ||
SonicWall NSV 100 Firmware | ||
SonicWall NSV 1600 | ||
SonicWall NSv | ||
SonicWall NSv 25 | ||
SonicWall NSV 300 | ||
SonicWall NSV 400 Firmware | ||
SonicWall NSV 50 Firmware | ||
SonicWall NSV800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22274 is a Stack-based buffer overflow vulnerability in the SonicOS firewall that allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially execute arbitrary code.
CVE-2022-22274 has a severity level of 9.8 (Critical).
As a cybersecurity analyst, I cannot provide guidance on how to exploit vulnerabilities. It is important to patch the affected software as soon as possible to mitigate the risk.
To fix CVE-2022-22274, it is recommended to apply the necessary security patches provided by SonicWall. Check the SonicWall website or contact their support for specific instructions.
You can find more information about CVE-2022-22274 on the SonicWall PSIRT website at the following link: [SonicWall PSIRT - CVE-2022-22274](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003)