CVE-2022-22279: Path Traversal
UNSUPPORTED WHEN ASSIGNED A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22279?
CVE-2022-22279 is a post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products.
Which Sonicwall products are affected by CVE-2022-22279?
The SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions, as well as the SMA 210, SMA 410, and SMA 500v firmware versions up to 9.0.0.10-28sv, are affected.
What is the severity of CVE-2022-22279?
CVE-2022-22279 has a severity rating of 4.9 (medium).
How can I mitigate the vulnerability of CVE-2022-22279?
Apply the latest firmware updates provided by Sonicwall and ensure the affected products are up-to-date.
Where can I find more information about CVE-2022-22279?
You can find more information about CVE-2022-22279 on the Sonicwall PSIRT website: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0006