Lucene search

K
nvd[email protected]NVD:CVE-2022-2915
HistoryAug 26, 2022 - 9:15 p.m.

CVE-2022-2915

2022-08-2621:15:08
CWE-122
CWE-787
web.nvd.nist.gov
5
sonicwall sma100
heap-based buffer overflow
remote attacker
dos
code execution

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.5%

A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) on the appliance or potentially lead to code execution. This vulnerability impacts 10.2.1.5-34sv and earlier versions.

Affected configurations

Nvd
Node
sonicwallsma_200_firmwareRange10.2.1.5-34sv
AND
sonicwallsma_200Match-
Node
sonicwallsma_210_firmwareRange10.2.1.5-34sv
AND
sonicwallsma_210Match-
Node
sonicwallsma_400_firmwareRange10.2.1.5-34sv
AND
sonicwallsma_400Match-
Node
sonicwallsma_410_firmwareRange10.2.1.5-34sv
AND
sonicwallsma_410Match-
Node
sonicwallsma_500v_firmwareRange10.2.1.5-34sv
AND
sonicwallsma_500vMatch-
VendorProductVersionCPE
sonicwallsma_200_firmware*cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
sonicwallsma_200-cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
sonicwallsma_210_firmware*cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
sonicwallsma_210-cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
sonicwallsma_400_firmware*cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
sonicwallsma_400-cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
sonicwallsma_410_firmware*cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
sonicwallsma_410-cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
sonicwallsma_500v_firmware*cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
sonicwallsma_500v-cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

66.5%

Related for NVD:CVE-2022-2915