CVE-2022-22274
CRITICAL EXPLOITEDSonicOS - Buffer Overflow
Title source: llmDescription
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.
Exploits (4)
nomisec
WORKING POC
19 stars
by BishopFox · poc
https://github.com/BishopFox/CVE-2022-22274_CVE-2023-0656
nomisec
WORKING POC
6 stars
by 4lucardSec · dos
https://github.com/4lucardSec/Sonic_CVE-2022-22274_poc
Scores
CVSS v3
9.8
EPSS
0.4700
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2024-09-12
CWE
CWE-121
CWE-787
Status
published
Products (2)
sonicwall/sonicos
< 7.0.1-5050
sonicwall/sonicosv
< 6.5.4.4-44v-21-1452
Published
Mar 25, 2022
Tracked Since
Feb 18, 2026