Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-47522


The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.5, indicating it requires adjacent network access but requires specific conditions to be met without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 59 products from ieee, from sonicwall, from sonicwall and 56 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2023, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2023-04-15T02:15:07.290

Last Modified

2025-02-06T16:15:31.443

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-290
  • Type: Secondary
    CWE-290

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ieee ieee_802.11 * Yes
Operating System sonicwall tz670_firmware - Yes
Hardware sonicwall tz670 - No
Operating System sonicwall tz570_firmware - Yes
Hardware sonicwall tz570 - No
Operating System sonicwall tz570p_firmware - Yes
Hardware sonicwall tz570p - No
Operating System sonicwall tz570w_firmware - Yes
Hardware sonicwall tz570w - No
Operating System sonicwall tz470_firmware - Yes
Hardware sonicwall tz470 - No
Operating System sonicwall tz470w_firmware - Yes
Hardware sonicwall tz470w - No
Operating System sonicwall tz370_firmware - Yes
Hardware sonicwall tz370 - No
Operating System sonicwall tz370w_firmware - Yes
Hardware sonicwall tz370w - No
Operating System sonicwall tz270_firmware - Yes
Hardware sonicwall tz270 - No
Operating System sonicwall tz270w_firmware - Yes
Hardware sonicwall tz270w - No
Operating System sonicwall tz600_firmware - Yes
Hardware sonicwall tz600 - No
Operating System sonicwall tz600p_firmware - Yes
Hardware sonicwall tz600p - No
Operating System sonicwall tz500_firmware - Yes
Hardware sonicwall tz500 - No
Operating System sonicwall tz500w_firmware - Yes
Hardware sonicwall tz500w - No
Operating System sonicwall tz400_firmware - Yes
Hardware sonicwall tz400 - No
Operating System sonicwall tz400w_firmware - Yes
Hardware sonicwall tz400w - No
Operating System sonicwall tz350_firmware - Yes
Hardware sonicwall tz350 - No
Operating System sonicwall tz350w_firmware - Yes
Hardware sonicwall tz350w - No
Operating System sonicwall tz300_firmware - Yes
Hardware sonicwall tz300 - No
Operating System sonicwall tz300p_firmware - Yes
Hardware sonicwall tz300p - No
Operating System sonicwall tz300w_firmware - Yes
Hardware sonicwall tz300w - No
Operating System sonicwall soho_250_firmware - Yes
Hardware sonicwall soho_250 - No
Operating System sonicwall soho_250w_firmware - Yes
Hardware sonicwall soho_250w - No
Operating System sonicwall sonicwave_231c_firmware - Yes
Hardware sonicwall sonicwave_231c - No
Operating System sonicwall sonicwave_224w_firmware - Yes
Hardware sonicwall sonicwave_224w - No
Operating System sonicwall sonicwave_432o_firmware - Yes
Hardware sonicwall sonicwave_432o - No
Operating System sonicwall sonicwave_621_firmware - Yes
Hardware sonicwall sonicwave_621 - No
Operating System sonicwall sonicwave_641_firmware - Yes
Hardware sonicwall sonicwave_641 - No
Operating System sonicwall sonicwave_681_firmware - Yes
Hardware sonicwall sonicwave_681 - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For ieee's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.