CVE-2022-22279

A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sonicwall:sra_1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sra_1200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:sra_4200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sra_4200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:43

Type Values Removed Values Added
Summary ** UNSUPPORTED WHEN ASSIGNED ** A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions. A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions

24 Jul 2023, 13:44

Type Values Removed Values Added
CWE CWE-287 CWE-22

Information

Published : 2022-04-13 06:15

Updated : 2024-08-03 03:16


NVD link : CVE-2022-22279

Mitre link : CVE-2022-22279

CVE.ORG link : CVE-2022-22279


JSON object : View

Products Affected

sonicwall

  • sma_410
  • sra_4200_firmware
  • sma_210
  • sma_410_firmware
  • sra_4200
  • sma_210_firmware
  • sma_500v
  • sra_1200
  • sma_500v_firmware
  • sra_1200_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-23

Relative Path Traversal