CVE-2022-22278 - CVE House
Back to Database
Status published High CVE-2022-22278

A vulnerability in SonicOS CFS (Content filtering service) returns a...

Vulnerability Description

A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22278

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SonicOS
Vulnerable Versions:
SonicOS Gen 7 TZ-Series 7.0.1-5030-R2007 and earlier versions., SonicOS Gen 7 NSa-Series 7.0.1-5030-R2007 and earlier versions., SonicOS Gen 7 NSv-Series 7.0.1.0-5030-1391 and earlier versions., SonicOS Gen 7 NSsp-Series 7.0.1-5030-R780 and earlier versions.

Timeline

Official Publish: April 27th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)