7.5
CWE
770
Advisory Published
Updated

CVE-2022-22278

First published: Wed Apr 27 2022(Updated: )

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

Credit: PSIRT@sonicwall.com

Affected SoftwareAffected VersionHow to fix
SonicWall TZ300P Firmware<7.0.1
SonicWall TZ300P Firmware
SonicWall TZ300W Firmware<7.0.1
SonicWall TZ300W Firmware
SonicWall TZ350W Firmware<7.0.1
SonicWall TZ350 Firmware
SonicWall TZ350W Firmware<7.0.1
SonicWall TZ350W Firmware
SonicWall NSSP 10700 Firmware<7.0.1.0
SonicWall NSSP 10700 Firmware
SonicWall NSSP 11700<7.0.1.0
SonicWall NSSP 11700
SonicWall NSSP 12400 Firmware<7.0.1.0
SonicWall NSSP 12400
Sonicwall Nssp 12800 Firmware<7.0.1.0
SonicWall NSSP 12800
SonicWall NSSP 13700<7.0.1.0
SonicWall NSSP 13700
SonicWall NSSP 15700<7.0.1.0
SonicWall NSSP 15700
SonicWall TZ370<7.0.1
SonicWall TZ370
SonicWall TZ370W<7.0.1
SonicWall TZ370W Firmware
SonicWall TZ400W Firmware<7.0.1
SonicWall TZ400W Firmware
SonicWall NSV 10 Firmware<7.0.1.0
SonicWall NSV 10 Firmware
SonicWall NSV 100<7.0.1.0
SonicWall NSV 100 Firmware
SonicWall NSV 1600<7.0.1.0
SonicWall NSV 1600
SonicWall NSV 200 Firmware<7.0.1.0
SonicWall NSv
SonicWall NSV 25<7.0.1.0
SonicWall NSV 25
SonicWall NSV 270<7.0.1.0
SonicWall NSV 270
SonicWall NSV 300 Firmware<7.0.1.0
SonicWall NSV 300
SonicWall NSV 400 Firmware<7.0.1.0
SonicWall NSV 400 Firmware
SonicWall NSV 470<7.0.1.0
SonicWall NSV 470 Firmware
SonicWall NSv 50<7.0.1.0
SonicWall NSV 50 Firmware
SonicWall NSV 800<7.0.1.0
SonicWall NSV800
SonicWall NSv 870<7.0.1.0
SonicWall NSv 870
SonicWall TZ400W Firmware<7.0.1
SonicWall TZ400W Firmware
SonicWall TZ470<7.0.1
SonicWall TZ470 Firmware
SonicWall TZ470<7.0.1
SonicWall TZ470W Firmware
SonicWall TZ500W Firmware<7.0.1
SonicWall TZ500W
SonicWall NSA 2650 Firmware<7.0.1
SonicWall NSA 2650
SonicWall NSA 2700 Firmware<7.0.1
SonicWall NSA 2700
SonicWall NSA 3650 Firmware<7.0.1
SonicWall NSA 3650 Firmware
SonicWall NSA 3700 Firmware<7.0.1
SonicWall NSA 3700 Firmware
SonicWall NSA 4650 Firmware<7.0.1
SonicWall NSA 4650 Firmware
SonicWall NSA 4700<7.0.1
SonicWall NSA 4700
SonicWall NSA 5650 Firmware<7.0.1
SonicWall NSA 5650
SonicWall NSA 5700 Firmware<7.0.1
SonicWall NSA 5700
SonicWall NSA 6650 Firmware<7.0.1
SonicWall NSA 6650
SonicWall NSA 6700 Firmware<7.0.1
SonicWall NSA 6700 Firmware
SonicWall NSA 9250 Firmware<7.0.1
SonicWall NSA 9250
SonicWall NSA 9450 Firmware<7.0.1
SonicWall NSA 9450
SonicWall NSA 9650 Firmware<7.0.1
SonicWall NSA 9650
SonicWall TZ500W Firmware<7.0.1
SonicWall TZ500W Firmware
SonicWall TZ570W<7.0.1
SonicWall TZ570 Firmware
SonicWall TZ570P<7.0.1
SonicWall TZ570P Firmware
SonicWall TZ570W<7.0.1
SonicWall TZ570W Firmware
SonicWall TZ600P Firmware<7.0.1
SonicWall TZ600
SonicWall TZ600P Firmware<7.0.1
SonicWall TZ 600P
SonicWall TZ670<7.0.1
SonicWall TZ670 Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-22278?

    The severity of CVE-2022-22278 is considered high due to its potential for causing a Denial of Service (DoS) attack.

  • How do I fix CVE-2022-22278?

    To fix CVE-2022-22278, it is recommended to upgrade to SonicOS versions higher than 7.0.1.

  • What types of devices are affected by CVE-2022-22278?

    CVE-2022-22278 affects SonicWall TZ series and NSSP devices running SonicOS versions below 7.0.1.

  • What kind of attack can CVE-2022-22278 lead to?

    CVE-2022-22278 can lead to an HTTP Denial of Service (DoS) attack by causing excessive 403 forbidden responses.

  • Is CVE-2022-22278 a known vulnerability?

    Yes, CVE-2022-22278 is a known vulnerability that was officially identified and documented for SonicWall devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203