7.5

CVE-2022-22278

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SonicwallTz300p Firmware Version < 7.0.1
   SonicwallTz300p Version-
SonicwallTz300w Firmware Version < 7.0.1
   SonicwallTz300w Version-
SonicwallTz350 Firmware Version < 7.0.1
   SonicwallTz350 Version-
SonicwallTz350w Firmware Version < 7.0.1
   SonicwallTz350w Version-
SonicwallNssp 10700 Firmware Version < 7.0.1.0
   SonicwallNssp 10700 Version-
SonicwallNssp 11700 Firmware Version < 7.0.1.0
   SonicwallNssp 11700 Version-
SonicwallNssp 12400 Firmware Version < 7.0.1.0
   SonicwallNssp 12400 Version-
SonicwallNssp 12800 Firmware Version < 7.0.1.0
   SonicwallNssp 12800 Version-
SonicwallNssp 13700 Firmware Version < 7.0.1.0
   SonicwallNssp 13700 Version-
SonicwallNssp 15700 Firmware Version < 7.0.1.0
   SonicwallNssp 15700 Version-
SonicwallTz370 Firmware Version < 7.0.1
   SonicwallTz370 Version-
SonicwallTz370w Firmware Version < 7.0.1
   SonicwallTz370w Version-
SonicwallTz400 Firmware Version < 7.0.1
   SonicwallTz400 Version-
SonicwallNsv 10 Firmware Version < 7.0.1.0
   SonicwallNsv 10 Version-
SonicwallNsv 100 Firmware Version < 7.0.1.0
   SonicwallNsv 100 Version-
SonicwallNsv 1600 Firmware Version < 7.0.1.0
   SonicwallNsv 1600 Version-
SonicwallNsv 200 Firmware Version < 7.0.1.0
   SonicwallNsv 200 Version-
SonicwallNsv 25 Firmware Version < 7.0.1.0
   SonicwallNsv 25 Version-
SonicwallNsv 270 Firmware Version < 7.0.1.0
   SonicwallNsv 270 Version-
SonicwallNsv 300 Firmware Version < 7.0.1.0
   SonicwallNsv 300 Version-
SonicwallNsv 400 Firmware Version < 7.0.1.0
   SonicwallNsv 400 Version-
SonicwallNsv 470 Firmware Version < 7.0.1.0
   SonicwallNsv 470 Version-
SonicwallNsv 50 Firmware Version < 7.0.1.0
   SonicwallNsv 50 Version-
SonicwallNsv 800 Firmware Version < 7.0.1.0
   SonicwallNsv 800 Version-
SonicwallNsv 870 Firmware Version < 7.0.1.0
   SonicwallNsv 870 Version-
SonicwallTz400w Firmware Version < 7.0.1
   SonicwallTz400w Version-
SonicwallTz470 Firmware Version < 7.0.1
   SonicwallTz470 Version-
SonicwallTz470w Firmware Version < 7.0.1
   SonicwallTz470w Version-
SonicwallTz500 Firmware Version < 7.0.1
   SonicwallTz500 Version-
SonicwallNsa 2650 Firmware Version < 7.0.1
   SonicwallNsa 2650 Version-
SonicwallNsa 2700 Firmware Version < 7.0.1
   SonicwallNsa 2700 Version-
SonicwallNsa 3650 Firmware Version < 7.0.1
   SonicwallNsa 3650 Version-
SonicwallNsa 3700 Firmware Version < 7.0.1
   SonicwallNsa 3700 Version-
SonicwallNsa 4650 Firmware Version < 7.0.1
   SonicwallNsa 4650 Version-
SonicwallNsa 4700 Firmware Version < 7.0.1
   SonicwallNsa 4700 Version-
SonicwallNsa 5650 Firmware Version < 7.0.1
   SonicwallNsa 5650 Version-
SonicwallNsa 5700 Firmware Version < 7.0.1
   SonicwallNsa 5700 Version-
SonicwallNsa 6650 Firmware Version < 7.0.1
   SonicwallNsa 6650 Version-
SonicwallNsa 6700 Firmware Version < 7.0.1
   SonicwallNsa 6700 Version-
SonicwallNsa 9250 Firmware Version < 7.0.1
   SonicwallNsa 9250 Version-
SonicwallNsa 9450 Firmware Version < 7.0.1
   SonicwallNsa 9450 Version-
SonicwallNsa 9650 Firmware Version < 7.0.1
   SonicwallNsa 9650 Version-
SonicwallTz500w Firmware Version < 7.0.1
   SonicwallTz500w Version-
SonicwallTz570 Firmware Version < 7.0.1
   SonicwallTz570 Version-
SonicwallTz570p Firmware Version < 7.0.1
   SonicwallTz570p Version-
SonicwallTz570w Firmware Version < 7.0.1
   SonicwallTz570w Version-
SonicwallTz600 Firmware Version < 7.0.1
   SonicwallTz600 Version-
SonicwallTz600p Firmware Version < 7.0.1
   SonicwallTz600p Version-
SonicwallTz670 Firmware Version < 7.0.1
   SonicwallTz670 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.492
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.