CVE-2022-22279

** UNSUPPORTED WHEN ASSIGNED ** A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sonicwall:sra_1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sra_1200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:sra_4200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sra_4200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

History

24 Jul 2023, 13:44

Type Values Removed Values Added
CWE CWE-287 CWE-22

21 Apr 2022, 15:23

Type Values Removed Values Added
References (CONFIRM) https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0006 - (CONFIRM) https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0006 - Vendor Advisory
CPE cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sra_1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sra_4200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sra_4200:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sra_1200:-:*:*:*:*:*:*:*
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.9

13 Apr 2022, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-13 06:15

Updated : 2024-05-17 02:05


NVD link : CVE-2022-22279

Mitre link : CVE-2022-22279

CVE.ORG link : CVE-2022-22279


JSON object : View

Products Affected

sonicwall

  • sra_1200_firmware
  • sma_210_firmware
  • sra_1200
  • sra_4200_firmware
  • sra_4200
  • sma_210
  • sma_500v
  • sma_410_firmware
  • sma_500v_firmware
  • sma_410
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-23

Relative Path Traversal