CVE-2022-22282

EUVD-2022-27429
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
sonicwallsma_6200_firmware
12.4.0
sonicwallsma_6200_firmware
12.4.1
sonicwallsma_6210_firmware
12.4.0
sonicwallsma_6210_firmware
12.4.1
sonicwallsma_7200_firmware
12.4.0
sonicwallsma_7200_firmware
12.4.1
sonicwallsma_7210_firmware
12.4.0
sonicwallsma_7210_firmware
12.4.1
sonicwallsma_8000v_firmware
12.4.0
sonicwallsma_8000v_firmware
12.4.1
𝑥
= Vulnerable software versions