CVE-2024-22397: XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22397?
CVE-2024-22397 is considered a high severity vulnerability due to its potential for remote exploitation by authenticated attackers.
How do I fix CVE-2024-22397?
To fix CVE-2024-22397, ensure that you apply the latest security patches provided by SonicWall for SonicOS.
Who is affected by CVE-2024-22397?
CVE-2024-22397 affects SonicWall SonicOS SSLVPN users, specifically those with admin privileges.
What type of vulnerability is CVE-2024-22397?
CVE-2024-22397 is a Cross-site Scripting (XSS) vulnerability that allows execution of arbitrary JavaScript code.
What are the potential impacts of CVE-2024-22397?
The potential impacts of CVE-2024-22397 include unauthorized access to sensitive data and the ability to manipulate web sessions.