CRITICAL
CVE-2021-20016
CVSS
9.8
KEV
Description
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
Summary dbcve.org
SQL injection vulnerability in SonicWall SMA100 SSL VPN product allows remote unauthenticated attackers to execute arbitrary SQL queries, potentially extracting usernames, passwords, and session information from the database.
Mitigation
Apply vendor security patches for SMA100 version 10.x; as an interim measure, implement a WAF or restrict VPN access to trusted IP ranges until patching is completed.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
40.04%
Probability of exploitation in next 30 days
98.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.