Severity
High
Analysis Summary
CVE-2022-22280
SonicWall Global Management System (GMS) and Analytics are vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
Impact
- Data Manipulation
Indicators Of Compromise
CVE
- CVE-2022-22280
Affected Vendors
Sonicwall
Affected Products
- SonicWall Global Management System 9.3.1-SP2-Hotfix1
- SonicWall Analytics 2.5.0.3-2520
Remediation
Refer to SonicWall Security Advisory for patch, upgrade or suggested workaround information.