CVE-2022-22282

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
sonicwallCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
sonicwallsma_6200_firmware
12.4.0
sonicwallsma_6200_firmware
12.4.1
sonicwallsma_6210_firmware
12.4.0
sonicwallsma_6210_firmware
12.4.1
sonicwallsma_7200_firmware
12.4.0
sonicwallsma_7200_firmware
12.4.1
sonicwallsma_7210_firmware
12.4.0
sonicwallsma_7210_firmware
12.4.1
sonicwallsma_8000v_firmware
12.4.0
sonicwallsma_8000v_firmware
12.4.1
𝑥
= Vulnerable software versions