ZeroHour
Security Affairspublished ()ingested @securityaffairs

SonicWall urges customers to fix SMA 1000 vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22282
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthoriz

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.

NVD description · AI analysis pending
9.88%
  • sonicwall sma 6200 firmware
  • sonicwall sma 6210 firmware
  • sonicwall sma 7200 firmware
  • +1 more
Full article236 words · extracted from securityaffairs.com · click to collapse

SonicWall warns customers to address several high-risk security flaws impacting its Secure Mobile Access (SMA) 1000 Series line of products.

SonicWall urges customers to address several high-risk security vulnerabilities affecting its Secure Mobile Access (SMA) 1000 Series line of products. An attacker can exploit the vulnerabilities to bypass authorization and, potentially, compromise vulnerable devices.

The first issue, tracked as CVE-2022-22282, in an unauthenticated access control bypass flaw, it affects SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions. The flaw was rated high severity.

“SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.” reads the description for this issue.

The vendor also addressed a hard-coded cryptographic key and an open redirect issue, the two flaws are rated as medium severity.

The SonicWall Product Security & Incident Response Team (PSIRT) said that it is now aware of attacks in the wild exploiting any of the above flaws. The company pointed out that there are no temporary mitigations.

“There are no temporary mitigations. SonicWall urges impacted customers to implement applicable patches as soon as possible.” continues the report.

The flaws does not impact SMA 1000 series running versions earlier than 12.4.0.

Below is the list of impacted platforms:

SonicWall strongly urges that organizations using the SMA 1000 series

Pierluigi Paganini

(SecurityAffairs – hacking, SMA)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/131247/security/sonicwall-urges-customers-to-fix-sma-1000-vulnerabilities.html