CVE-2024-22397: SonicWall SonicOS

High severity, CVSS 8.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.

Affected products

  • SonicWall SonicOS: up to and including 7.0.1-5145; up to and including 7.1.1-7047

Published 2024-03-14. Last modified 2026-06-17.