First published: Wed Apr 27 2022(Updated: )
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall TZ300P Firmware | <7.0.1 | |
SonicWall TZ300P Firmware | ||
SonicWall TZ300W Firmware | <7.0.1 | |
SonicWall TZ300W Firmware | ||
SonicWall TZ350W Firmware | <7.0.1 | |
SonicWall TZ350 Firmware | ||
SonicWall TZ350W Firmware | <7.0.1 | |
SonicWall TZ350W Firmware | ||
SonicWall NSSP 10700 Firmware | <7.0.1.0 | |
SonicWall NSSP 10700 Firmware | ||
SonicWall NSSP 11700 | <7.0.1.0 | |
SonicWall NSSP 11700 | ||
SonicWall NSSP 12400 Firmware | <7.0.1.0 | |
SonicWall NSSP 12400 | ||
Sonicwall Nssp 12800 Firmware | <7.0.1.0 | |
SonicWall NSSP 12800 | ||
SonicWall NSSP 13700 | <7.0.1.0 | |
SonicWall NSSP 13700 | ||
SonicWall NSSP 15700 | <7.0.1.0 | |
SonicWall NSSP 15700 | ||
SonicWall TZ370 | <7.0.1 | |
SonicWall TZ370 | ||
SonicWall TZ370W | <7.0.1 | |
SonicWall TZ370W Firmware | ||
SonicWall TZ400W Firmware | <7.0.1 | |
SonicWall TZ400W Firmware | ||
SonicWall NSV 10 Firmware | <7.0.1.0 | |
SonicWall NSV 10 Firmware | ||
SonicWall NSV 100 | <7.0.1.0 | |
SonicWall NSV 100 Firmware | ||
SonicWall NSV 1600 | <7.0.1.0 | |
SonicWall NSV 1600 | ||
SonicWall NSV 200 Firmware | <7.0.1.0 | |
SonicWall NSv | ||
SonicWall NSV 25 | <7.0.1.0 | |
SonicWall NSV 25 | ||
SonicWall NSV 270 | <7.0.1.0 | |
SonicWall NSV 270 | ||
SonicWall NSV 300 Firmware | <7.0.1.0 | |
SonicWall NSV 300 | ||
SonicWall NSV 400 Firmware | <7.0.1.0 | |
SonicWall NSV 400 Firmware | ||
SonicWall NSV 470 | <7.0.1.0 | |
SonicWall NSV 470 Firmware | ||
SonicWall NSv 50 | <7.0.1.0 | |
SonicWall NSV 50 Firmware | ||
SonicWall NSV 800 | <7.0.1.0 | |
SonicWall NSV800 | ||
SonicWall NSv 870 | <7.0.1.0 | |
SonicWall NSv 870 | ||
SonicWall TZ400W Firmware | <7.0.1 | |
SonicWall TZ400W Firmware | ||
SonicWall TZ470 | <7.0.1 | |
SonicWall TZ470 Firmware | ||
SonicWall TZ470 | <7.0.1 | |
SonicWall TZ470W Firmware | ||
SonicWall TZ500W Firmware | <7.0.1 | |
SonicWall TZ500W | ||
SonicWall NSA 2650 Firmware | <7.0.1 | |
SonicWall NSA 2650 | ||
SonicWall NSA 2700 Firmware | <7.0.1 | |
SonicWall NSA 2700 | ||
SonicWall NSA 3650 Firmware | <7.0.1 | |
SonicWall NSA 3650 Firmware | ||
SonicWall NSA 3700 Firmware | <7.0.1 | |
SonicWall NSA 3700 Firmware | ||
SonicWall NSA 4650 Firmware | <7.0.1 | |
SonicWall NSA 4650 Firmware | ||
SonicWall NSA 4700 | <7.0.1 | |
SonicWall NSA 4700 | ||
SonicWall NSA 5650 Firmware | <7.0.1 | |
SonicWall NSA 5650 | ||
SonicWall NSA 5700 Firmware | <7.0.1 | |
SonicWall NSA 5700 | ||
SonicWall NSA 6650 Firmware | <7.0.1 | |
SonicWall NSA 6650 | ||
SonicWall NSA 6700 Firmware | <7.0.1 | |
SonicWall NSA 6700 Firmware | ||
SonicWall NSA 9250 Firmware | <7.0.1 | |
SonicWall NSA 9250 | ||
SonicWall NSA 9450 Firmware | <7.0.1 | |
SonicWall NSA 9450 | ||
SonicWall NSA 9650 Firmware | <7.0.1 | |
SonicWall NSA 9650 | ||
SonicWall TZ500W Firmware | <7.0.1 | |
SonicWall TZ500W Firmware | ||
SonicWall TZ570W | <7.0.1 | |
SonicWall TZ570 Firmware | ||
SonicWall TZ570P | <7.0.1 | |
SonicWall TZ570P Firmware | ||
SonicWall TZ570W | <7.0.1 | |
SonicWall TZ570W Firmware | ||
SonicWall TZ600P Firmware | <7.0.1 | |
SonicWall TZ600 | ||
SonicWall TZ600P Firmware | <7.0.1 | |
SonicWall TZ 600P | ||
SonicWall TZ670 | <7.0.1 | |
SonicWall TZ670 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22278 is considered high due to its potential for causing a Denial of Service (DoS) attack.
To fix CVE-2022-22278, it is recommended to upgrade to SonicOS versions higher than 7.0.1.
CVE-2022-22278 affects SonicWall TZ series and NSSP devices running SonicOS versions below 7.0.1.
CVE-2022-22278 can lead to an HTTP Denial of Service (DoS) attack by causing excessive 403 forbidden responses.
Yes, CVE-2022-22278 is a known vulnerability that was officially identified and documented for SonicWall devices.