Vulnerability Details CVE-2022-22273
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and Secure Mobile Access (SMA) 100 series products running older firmware 9.0.0.9-26sv and earlier versions
Exploit prediction scoring system (EPSS) score
EPSS Score 0.059
EPSS Ranking 90.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-22273
-
cpe:2.3:h:sonicwall:sma_200:-
-
cpe:2.3:h:sonicwall:sma_210:-
-
cpe:2.3:h:sonicwall:sma_400:-
-
cpe:2.3:h:sonicwall:sma_410:-
-
cpe:2.3:h:sonicwall:sma_500v:-
-
cpe:2.3:h:sonicwall:sra_1200:-
-
cpe:2.3:h:sonicwall:sra_1600:-
-
cpe:2.3:h:sonicwall:sra_4200:-
-
cpe:2.3:h:sonicwall:sra_4600:-
-
cpe:2.3:o:sonicwall:sma_200_firmware:-
-
cpe:2.3:o:sonicwall:sma_210_firmware:-
-
cpe:2.3:o:sonicwall:sma_210_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_400_firmware:-
-
cpe:2.3:o:sonicwall:sma_410_firmware:-
-
cpe:2.3:o:sonicwall:sma_410_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_500v_firmware:-
-
cpe:2.3:o:sonicwall:sma_500v_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_500v_firmware:9.0.0.9-26sv
-
cpe:2.3:o:sonicwall:sra_1200_firmware:-
-
cpe:2.3:o:sonicwall:sra_1200_firmware:9.0.0.5-19sv
-
cpe:2.3:o:sonicwall:sra_1600_firmware:-
-
cpe:2.3:o:sonicwall:sra_1600_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sra_4200_firmware:-
-
cpe:2.3:o:sonicwall:sra_4200_firmware:9.0.0.5-19sv
-
cpe:2.3:o:sonicwall:sra_4600_firmware:-
-
cpe:2.3:o:sonicwall:sra_4600_firmware:8.0.0.0