PT-2022-6179 · Sonicwall · Sonicos

Published

2022-03-25

·

Updated

2026-03-01

·

CVE-2022-22274

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicOS (affected versions not specified)
Description A Stack-based buffer overflow vulnerability in SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall. The vulnerability is related to the web interface management of the SonicOS operating system and is associated with the possibility of a stack buffer overflow. It is estimated that over 178,000 SonicWall next-generation firewalls with exposed management interfaces are potentially affected.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-00346
CVE-2022-22274

Affected Products

Sonicos