CVE-2022-2323

Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host system. This vulnerability impacts SonicWall Switch 1.1.1.0-2s and earlier versions
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
sonicwallCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
sonicwallsws12-10fpoe_firmware
𝑥
< 1.2.0.0-3
sonicwallsws12-8_firmware
𝑥
< 1.2.0.0-3
sonicwallsws12-8poe_firmware
𝑥
< 1.2.0.0-3
sonicwallsws14-24_firmware
𝑥
< 1.2.0.0-3
sonicwallsws14-24fpoe_firmware
𝑥
< 1.2.0.0-3
sonicwallsws14-48_firmware
𝑥
< 1.2.0.0-3
sonicwallsws14-48fpoe_firmware
𝑥
< 1.2.0.0-3
𝑥
= Vulnerable software versions