CVE-2022-22273
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- sonicwall/sma 200 firmware · sonicwall/sma 210 firmware · sonicwall/sma 400 firmware · sonicwall/sma 410 firmware · sonicwall/sma 500v firmware · sonicwall/sra 4200 firmware · sonicwall/sra 4600 firmware · sonicwall/sra 1600 firmware · sonicwall/sra 1200 firmware
- Source
- PSIRT@sonicwall.com
References
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0001Patch, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0001Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.