7.5
CVE-2022-2324
- EPSS 0.11%
- Veröffentlicht 29.07.2022 21:15:09
- Zuletzt bearbeitet 31.10.2025 15:02:03
- Quelle PSIRT@sonicwall.com
- CVE-Watchlists
- Unerledigt
Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Hosted Email Security Version <= 10.0.17.7319
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.299 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-358 Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.