CVE-2022-1703

Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
sonicwallCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
sonicwallsma_210_firmware
𝑥
≤ 10.2.1.4-31sv
sonicwallsma_410_firmware
𝑥
≤ 10.2.1.4-31sv
sonicwallsma_500v_firmware
𝑥
≤ 10.2.1.4-31sv
sonicwallsma_210_firmware
𝑥
≤ 10.2.0.9-41sv
sonicwallsma_410_firmware
𝑥
≤ 10.2.0.9-41sv
sonicwallsma_500v_firmware
𝑥
≤ 10.2.0.9-41sv
𝑥
= Vulnerable software versions