ZeroHour

CVE-2022-22273

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions

Vendors
sonicwall
Products
sma 200 firmware, sma 210 firmware, sma 400 firmware, sma 410 firmware, sma 500v firmware, sra 4200 firmware, sra 4600 firmware, sra 1600 firmware, sra 1200 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.