CVE-2022-22278

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/04/2022
Last modified:
06/05/2022

Description

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sonicwall:tz300p_firmware:*:*:*:*:*:*:*:* 7.0.1 (excluding)
cpe:2.3:h:sonicwall:tz300p:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:tz300w_firmware:*:*:*:*:*:*:*:* 7.0.1 (excluding)
cpe:2.3:h:sonicwall:tz300w:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:tz350_firmware:*:*:*:*:*:*:*:* 7.0.1 (excluding)
cpe:2.3:h:sonicwall:tz350:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:tz350w_firmware:*:*:*:*:*:*:*:* 7.0.1 (excluding)
cpe:2.3:h:sonicwall:tz350w:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:nssp_10700_firmware:*:*:*:*:*:*:*:* 7.0.1.0 (excluding)
cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:nssp_11700_firmware:*:*:*:*:*:*:*:* 7.0.1.0 (excluding)
cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:nssp_12400_firmware:*:*:*:*:*:*:*:* 7.0.1.0 (excluding)
cpe:2.3:h:sonicwall:nssp_12400:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:nssp_12800_firmware:*:*:*:*:*:*:*:* 7.0.1.0 (excluding)


References to Advisories, Solutions, and Tools