CVE-2022-22274

CRITICAL EXPLOITED

SonicOS - Buffer Overflow

Title source: llm

Description

A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.

Exploits (4)

nomisec WORKING POC 19 stars
by BishopFox · poc
https://github.com/BishopFox/CVE-2022-22274_CVE-2023-0656
nomisec WORKING POC 6 stars
by 4lucardSec · dos
https://github.com/4lucardSec/Sonic_CVE-2022-22274_poc
nomisec WORKING POC
by forthisvideo · dos
https://github.com/forthisvideo/CVE-2022-22274_poc
inthewild WORKING POC
poc
https://github.com/pwneddr/sonic_cve-2022-22274_poc

Scores

CVSS v3 9.8
EPSS 0.4700
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2024-09-12
CWE
CWE-121 CWE-787
Status published
Products (2)
sonicwall/sonicos < 7.0.1-5050
sonicwall/sonicosv < 6.5.4.4-44v-21-1452
Published Mar 25, 2022
Tracked Since Feb 18, 2026