CVE-2022-2323
Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host system. This vulnerability impacts SonicWall Switch 1.1.1.0-2s and earlier versions
Published:Jul 29, 2022
Last Modified:Nov 21, 2024
EPS:Jul 29, 2022
EPSS Score:0.01311
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Sonicwall
Product
Sws12-10fpoe
Sonicwall
Sws12-10fpoe
Vendor
Sonicwall
Product
Sws12-10fpoe Firmware
Sonicwall
Sws12-10fpoe Firmware
Vendor
Sonicwall
Product
Sws12-8
Sonicwall
Sws12-8
Vendor
Sonicwall
Product
Sws12-8 Firmware
Sonicwall
Sws12-8 Firmware
Vendor
Sonicwall
Product
Sws12-8poe
Sonicwall
Sws12-8poe
Vendor
Sonicwall
Product
Sws12-8poe Firmware
Sonicwall
Sws12-8poe Firmware
Vendor
Sonicwall
Product
Sws14-24
Sonicwall
Sws14-24
Vendor
Sonicwall
Product
Sws14-24 Firmware
Sonicwall
Sws14-24 Firmware
Vendor
Sonicwall
Product
Sws14-24fpoe
Sonicwall
Sws14-24fpoe
Vendor
Sonicwall
Product
Sws14-24fpoe Firmware
Sonicwall
Sws14-24fpoe Firmware
Vendor
Sonicwall
Product
Sws14-48
Sonicwall
Sws14-48
Vendor
Sonicwall
Product
Sws14-48 Firmware
Sonicwall
Sws14-48 Firmware
Vendor
Sonicwall
Product
Sws14-48fpoe
Sonicwall
Sws14-48fpoe
Vendor
Sonicwall
Product
Sws14-48fpoe Firmware
Sonicwall
Sws14-48fpoe Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
