Open Redirection Vulnerability in SonicWall SMA1000 Series Firmware
CVE-2022-1702

6.1MEDIUM

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
13 May 2022

Summary

The SonicWall SMA1000 series firmware versions 12.4.0 and 12.4.1-02965, along with earlier versions, are vulnerable to an open redirection attack. This flaw allows an attacker to manipulate user-controlled input to redirect users to unintended external sites, potentially leading to phishing schemes or other malicious activities. Proper security measures are crucial to mitigate such vulnerabilities and safeguard user data. For more details, visit the official SonicWall PSIRT page.

Affected Version(s)

SonicWall SMA1000 12.4.0

SonicWall SMA1000 12.4.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.