« Volver al listado

CVE-2022-22282

Estado: ModificadaCrítica (9.8)—

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-22282",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@sonicwall.com",
      "affectedData": [
        {
          "vendor": "SonicWall",
          "product": "SonicWall SMA1000",
          "versions": [
            {
              "status": "affected",
              "version": "12.4.0"
            },
            {
              "status": "affected",
              "version": "12.4.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-13T20:15:08.133",
  "references": [
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0009",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT@sonicwall.com"
    },
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0009",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "PSIRT@sonicwall.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an unauthorized actor leading to Improper Access Control vulnerability."
    },
    {
      "lang": "es",
      "value": "El firmware de la serie SonicWall SMA1000 versiones 12.4.0, 12.4.1-02965 y versiones anteriores, restringe incorrectamente el acceso a un recurso mediante conexiones HTTP de un actor no autorizado, conllevando a una vulnerabilidad de control de acceso inapropiado"
    }
  ],
  "lastModified": "2026-06-17T04:28:10.150",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_6200_firmware:12.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17505971-4213-4CD8-BFCA-C2709ED1D7A8"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_6200_firmware:12.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AD1484C-6DC2-40E8-A423-391F75809A07"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sonicwall:sma_6200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "17BDC1B0-BE6A-4680-A78E-5338AD709095"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_6210_firmware:12.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9CAF7029-6661-4935-BFF5-DAF27B8D63A7"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_6210_firmware:12.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8183E157-625A-4503-B40A-9CF007B8D764"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sonicwall:sma_6210:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0734D1E1-2F59-4832-875F-AB03994B8992"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_7200_firmware:12.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "43F5B5E9-BB13-4222-816D-961EEE2F05A4"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_7200_firmware:12.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6988E176-25D8-42E8-918F-E0C8BD5AC41D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sonicwall:sma_7200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4C366A02-074C-4F98-AE68-30E0FF85CD00"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_7210_firmware:12.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "311646FD-B277-450D-8B15-00E38A181794"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_7210_firmware:12.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D114762-179F-42A3-A3D5-07F288EA1A39"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sonicwall:sma_7210:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A15BA659-19D1-49AA-B249-EAE5E63B9B9A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_8000v_firmware:12.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDBA4EA4-361A-42F2-B58E-D2327E3FB7D9"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sma_8000v_firmware:12.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "806B901C-82C1-4C5F-8C90-0A324F1B676E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:sonicwall:sma_8000v:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "83EBB751-21AF-4B5F-BB6D-A18FC760781F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "PSIRT@sonicwall.com"
}