HIGH · 7.5

CVE-2022-22278

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacke...

Vulnerability Description

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
SonicwallTz300P Firmware< 7.0.1
SonicwallTz300P-
SonicwallTz300W Firmware< 7.0.1
SonicwallTz300W-
SonicwallTz350 Firmware< 7.0.1
SonicwallTz350-
SonicwallTz350W Firmware< 7.0.1
SonicwallTz350W-
SonicwallNssp 10700 Firmware< 7.0.1.0
SonicwallNssp 10700-
SonicwallNssp 11700 Firmware< 7.0.1.0
SonicwallNssp 11700-
SonicwallNssp 12400 Firmware< 7.0.1.0
SonicwallNssp 12400-
SonicwallNssp 12800 Firmware< 7.0.1.0
SonicwallNssp 12800-
SonicwallNssp 13700 Firmware< 7.0.1.0
SonicwallNssp 13700-
SonicwallNssp 15700 Firmware< 7.0.1.0
SonicwallNssp 15700-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22278?

CVE-2022-22278 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacke...

How severe is CVE-2022-22278?

CVE-2022-22278 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-22278?

Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Tz300P Firmware, Sonicwall Tz300P, Sonicwall Tz300W Firmware, Sonicwall Tz300W, Sonicwall Tz350 Firmware.