Lucene search

K
cveSonicwallCVE-2022-2915
HistoryAug 26, 2022 - 9:15 p.m.

CVE-2022-2915

2022-08-2621:15:08
CWE-787
CWE-122
sonicwall
web.nvd.nist.gov
38
10
cve-2022-2915
sonicwall
sma100
heap-based buffer overflow
remote authentication
dos
code execution

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.003

Percentile

66.5%

A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and earlier versions.

Affected configurations

Nvd
Node
sonicwallsma_200_firmwareRange≀10.2.1.5-34sv
AND
sonicwallsma_200Match-
Node
sonicwallsma_210_firmwareRange≀10.2.1.5-34sv
AND
sonicwallsma_210Match-
Node
sonicwallsma_400_firmwareRange≀10.2.1.5-34sv
AND
sonicwallsma_400Match-
Node
sonicwallsma_410_firmwareRange≀10.2.1.5-34sv
AND
sonicwallsma_410Match-
Node
sonicwallsma_500v_firmwareRange≀10.2.1.5-34sv
AND
sonicwallsma_500vMatch-
VendorProductVersionCPE
sonicwallsma_200_firmware*cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
sonicwallsma_200-cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
sonicwallsma_210_firmware*cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
sonicwallsma_210-cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
sonicwallsma_400_firmware*cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
sonicwallsma_400-cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
sonicwallsma_410_firmware*cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
sonicwallsma_410-cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
sonicwallsma_500v_firmware*cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
sonicwallsma_500v-cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "SMA100",
    "vendor": "SonicWall",
    "versions": [
      {
        "status": "affected",
        "version": "10.2.1.5-34sv and earlier"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.003

Percentile

66.5%

Related for CVE-2022-2915