Vulnerability record · CVE-2022-22274 · published 25 March 2022
CVE-2022-22274: SonicOS HTTP request stack buffer overflow
Sonicwall · Sonicos
SonicOS and SonicOSv contain a stack-based buffer overflow reachable through an HTTP request. A remote unauthenticated attacker can trigger it to crash the firewall or potentially execute code. Because the vulnerable component is the perimeter firewall itself, a successful exploit undermines the device that is supposed to enforce network boundaries.
Description
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network, unauthenticated, no-interaction reachability and a very high EPSS score make this a top-priority perimeter device flaw despite the absence of KEV listing.
What it is
SonicOS and SonicOSv contain a stack-based buffer overflow reachable through an HTTP request. A remote unauthenticated attacker can trigger it to crash the firewall or potentially execute code. Because the vulnerable component is the perimeter firewall itself, a successful exploit undermines the device that is supposed to enforce network boundaries.
Impact
An attacker can cause denial of service against the firewall, disrupting all traffic it protects, or potentially achieve code execution with the privileges of the affected service.
Attack surface
The flaw is reached over the network via an HTTP request to the SonicOS management interface, with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is very high at 0.755 (99.5th percentile), indicating substantial predicted exploitation activity; the only references are vendor advisories, so no public exploit details are confirmed in this record.
What to do
- Apply the SonicWall PSIRT fix for SNWLID-2022-0003 on all affected SonicOS and SonicOSv instances.
- Restrict HTTP/HTTPS management access to trusted administrative networks and disable WAN-side management where not required.
- Place management interfaces behind a VPN or dedicated out-of-band path rather than exposing them to the internet.
- Monitor vendor advisories for updated builds and verify firmware versions against the fixed release.
- Segment firewall management traffic and log all access attempts to the management interface.
Detection
- Alert on crashes, unexpected reboots or service restarts of SonicOS/SonicOSv devices.
- Inspect HTTP requests to the management interface for oversized or malformed parameters and headers.
- Correlate firewall management access logs with anomalous source IPs or scanning activity.
- Monitor for post-exploitation behavior such as new processes, config changes or outbound connections from the firewall.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003 | Vendor Advisory |
Track CVE-2022-22274 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22274), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.