CVE-2022-22275: High severity sonicwall sonicos vulnerability
Published Apr 27, 2022
·Updated
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.
Affected Software
55 affected components
SonicWall SonicOS>=7.0.0.0<=7.0.1-5030-r2007
SonicWall Nsa 2650
SonicWall Nsa 2700
SonicWall Nsa 3650
SonicWall Nsa 3700
SonicWall Nsa 4650
SonicWall Nsa 4700
SonicWall Nsa 5650
SonicWall Nsa 5700
SonicWall Nsa 6650
SonicWall Nsa 6700
SonicWall Nsa 9250
SonicWall Nsa 9450
SonicWall Nsa 9650
SonicWall Soho 250
SonicWall Soho 250w
SonicWall Tz270
SonicWall Tz270w
SonicWall Tz300
SonicWall Tz300p
SonicWall Tz300w
SonicWall Tz350
SonicWall Tz350w
SonicWall Tz370
SonicWall Tz370w
SonicWall Tz400
SonicWall Tz400w
SonicWall Tz470
SonicWall Tz470w
SonicWall Tz500
SonicWall Tz500w
SonicWall Tz570
SonicWall Tz570p
SonicWall Tz570w
SonicWall Tz600
SonicWall Tz600p
SonicWall Tz670
SonicWall SonicOS>=7.0.0.0<=7.0.1.0-5030-1391
SonicWall Nsv 10
SonicWall Nsv 100
SonicWall Nsv 200
SonicWall Nsv 25
SonicWall Nsv 270
SonicWall Nsv 300
SonicWall Nsv 400
SonicWall Nsv 470
SonicWall Nsv 50
SonicWall Nsv 800
SonicWall Nsv 870
SonicWall SonicOS>=7.0.0.0<=7.0.1-5030-r780
SonicWall Nssp 10700
SonicWall Nssp 11700
SonicWall Nssp 12400
SonicWall Nssp 12800
SonicWall Nssp 13700
Event History
Apr 27, 2022
CVE Published
via MITRE·04:25 PM
Data Sourced
via MITRE·04:25 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-22275?
CVE-2022-22275 is a vulnerability that allows for improper restriction of TCP communication channel in HTTP/S inbound traffic, potentially resulting in a Denial of Service (DoS) attack.
2
Which software is affected by CVE-2022-22275?
SonicWall SonicOS versions 7.0.0.0 to 7.0.1-5030-r2007 are affected by CVE-2022-22275.
3
What is the severity of CVE-2022-22275?
CVE-2022-22275 has a severity rating of 7.5, indicating a high severity.
4
How can I fix CVE-2022-22275?
To fix CVE-2022-22275, it is recommended to update to a patched version of SonicWall SonicOS.
5
Where can I find more information about CVE-2022-22275?
You can find more information about CVE-2022-22275 on the SonicWall PSIRT website.