CVE-2022-22273
17.03.2022, 02:15
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sonicwall | sma_200_firmware | 𝑥 ≤ 9.0.0.9-26sv |
| sonicwall | sma_210_firmware | 𝑥 ≤ 9.0.0.9-26sv |
| sonicwall | sma_400_firmware | 𝑥 ≤ 9.0.0.9-26sv |
| sonicwall | sma_410_firmware | 𝑥 ≤ 9.0.0.9-26sv |
| sonicwall | sma_500v_firmware | 𝑥 ≤ 9.0.0.9-26sv |
| sonicwall | sra_4200_firmware | 𝑥 ≤ 9.0.0.5-19sv |
| sonicwall | sra_4600_firmware | 𝑥 ≤ 9.0.0.5-19sv |
| sonicwall | sra_1600_firmware | 𝑥 ≤ 9.0.0.5-19sv |
| sonicwall | sra_1200_firmware | 𝑥 ≤ 9.0.0.5-19sv |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| sonicwall | sma_100 | 𝑥 ≤ 9.0.0.9-26sv | ADP |
| sonicwall | sra | 𝑥 ≤ 9.0.0.5-19sv | ADP |