CVE-2022-1703

Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to...

Basic Information

CVE State
PUBLISHED
Reserved Date
May 12, 2022
Published Date
June 03, 2022
Last Updated
August 03, 2024
Vendor
SonicWall
Product
SMA100
Description
Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

9.0

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Exploit Status

Exploited in the Wild
Yes (2025-10-26 22:32:42 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-10-26 22:32:42 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel