Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.
CVE ID: CVE-2024-22397
CVSS Base Severity: HIGH
CVSS Base Score: 8.3
Vendor: SonicWall
Product: SonicOS
EPSS Score: 0.12% (probability of being exploited)
EPSS Percentile: 32.54% (scored less or equal to compared to others)
EPSS Date: 2025-04-25 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false