CVE-2022-2323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
29/07/2022
Last modified:
08/08/2022

Description

Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host system. This vulnerability impacts SonicWall Switch 1.1.1.0-2s and earlier versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sonicwall:sws12-10fpoe_firmware:*:*:*:*:*:*:*:* 1.2.0.0-3 (excluding)
cpe:2.3:h:sonicwall:sws12-10fpoe:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sws12-8_firmware:*:*:*:*:*:*:*:* 1.2.0.0-3 (excluding)
cpe:2.3:h:sonicwall:sws12-8:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sws12-8poe_firmware:*:*:*:*:*:*:*:* 1.2.0.0-3 (excluding)
cpe:2.3:h:sonicwall:sws12-8poe:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sws14-24_firmware:*:*:*:*:*:*:*:* 1.2.0.0-3 (excluding)
cpe:2.3:h:sonicwall:sws14-24:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sws14-24fpoe_firmware:*:*:*:*:*:*:*:* 1.2.0.0-3 (excluding)
cpe:2.3:h:sonicwall:sws14-24fpoe:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sws14-48_firmware:*:*:*:*:*:*:*:* 1.2.0.0-3 (excluding)
cpe:2.3:h:sonicwall:sws14-48:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sws14-48fpoe_firmware:*:*:*:*:*:*:*:* 1.2.0.0-3 (excluding)
cpe:2.3:h:sonicwall:sws14-48fpoe:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools