CRITICAL

CVE-2021-20016

Sonicwall Sma 100 Firmware 2021-02-04 CVSS v3.1
CVSS
9.8
KEV

Description

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

Summary dbcve.org

SQL injection vulnerability in SonicWall SMA100 SSL VPN product allows remote unauthenticated attackers to execute arbitrary SQL queries, potentially extracting usernames, passwords, and session information from the database.

Mitigation

Apply vendor security patches for SMA100 version 10.x; as an interim measure, implement a WAF or restrict VPN access to trusted IP ranges until patching is completed.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

40.04%
Probability of exploitation in next 30 days
98.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE