CVE-2022-22278

HIGHCVSS 7.5/10EPSS 0.88%

Last modified

CVE-2022-22278 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack. EPSS estimates a 0.88% chance of exploitation in the next 30 days.

Description

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.88%

54.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SonicwallTz300p Firmware< 7.0.1
SonicwallTz300w Firmware< 7.0.1
SonicwallTz350 Firmware< 7.0.1
SonicwallTz350w Firmware< 7.0.1
SonicwallNssp 10700 Firmware< 7.0.1.0
SonicwallNssp 11700 Firmware< 7.0.1.0
SonicwallNssp 12400 Firmware< 7.0.1.0
SonicwallNssp 12800 Firmware< 7.0.1.0
SonicwallNssp 13700 Firmware< 7.0.1.0
SonicwallNssp 15700 Firmware< 7.0.1.0
SonicwallTz370 Firmware< 7.0.1
SonicwallTz370w Firmware< 7.0.1
SonicwallTz400 Firmware< 7.0.1
SonicwallNsv 10 Firmware< 7.0.1.0
SonicwallNsv 100 Firmware< 7.0.1.0
SonicwallNsv 1600 Firmware< 7.0.1.0
SonicwallNsv 200 Firmware< 7.0.1.0
SonicwallNsv 25 Firmware< 7.0.1.0
SonicwallNsv 270 Firmware< 7.0.1.0
SonicwallNsv 300 Firmware< 7.0.1.0
SonicwallNsv 400 Firmware< 7.0.1.0
SonicwallNsv 470 Firmware< 7.0.1.0
SonicwallNsv 50 Firmware< 7.0.1.0
SonicwallNsv 800 Firmware< 7.0.1.0
SonicwallNsv 870 Firmware< 7.0.1.0
SonicwallTz400w Firmware< 7.0.1
SonicwallTz470 Firmware< 7.0.1
SonicwallTz470w Firmware< 7.0.1
SonicwallTz500 Firmware< 7.0.1
SonicwallNsa 2650 Firmware< 7.0.1
SonicwallNsa 2700 Firmware< 7.0.1
SonicwallNsa 3650 Firmware< 7.0.1
SonicwallNsa 3700 Firmware< 7.0.1
SonicwallNsa 4650 Firmware< 7.0.1
SonicwallNsa 4700 Firmware< 7.0.1
SonicwallNsa 5650 Firmware< 7.0.1
SonicwallNsa 5700 Firmware< 7.0.1
SonicwallNsa 6650 Firmware< 7.0.1
SonicwallNsa 6700 Firmware< 7.0.1
SonicwallNsa 9250 Firmware< 7.0.1
SonicwallNsa 9450 Firmware< 7.0.1
SonicwallNsa 9650 Firmware< 7.0.1
SonicwallTz500w Firmware< 7.0.1
SonicwallTz570 Firmware< 7.0.1
SonicwallTz570p Firmware< 7.0.1
SonicwallTz570w Firmware< 7.0.1
SonicwallTz600 Firmware< 7.0.1
SonicwallTz600p Firmware< 7.0.1
SonicwallTz670 Firmware< 7.0.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-22278?
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack
How severe is CVE-2022-22278?
CVE-2022-22278 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 0.88% probability of exploitation in the next 30 days.
How do I fix CVE-2022-22278?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-22278?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST