SonicWall Releases Security Update for SonicOS
Security update addresses a critical vulnerability that could allow a DoS attack or lead to RCE
Summary
Security update addresses a critical vulnerability that could allow a DoS attack or lead to RCE
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
SonicWall has released security updates to address a critical stack-based buffer overflow vulnerability in the SonicOS via HTTP request. This vulnerability, tracked as CVE-2022-22274, could allow a remote unauthenticated attacker to carry out a denial-of-service (DoS) attack or potentially cause remote code execution (RCE) in the firewall.
Remediation advice
Affected organisations are encouraged to review the SonicWall security advisory SNWLID-2022-0003 and Critical Unauthenticated Stack-Based Buffer Overflow Vulnerability In SonicOS security notification page and apply the relevant updates or workarounds.
Definitive source of threat updates
Last edited: 29 March 2022 3:38 pm