MEDIUM

CVE-2021-20035

Sonicwall Sma 200 Firmware 2021-09-27 CVSS v3.1
CVSS
6.5
KEV

Description

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.

Summary dbcve.org

Command injection vulnerability in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary shell commands, which execute with the privileges of the 'nobody' user, potentially leading to denial of service.

Mitigation

Implement proper input validation and sanitization for all user-supplied parameters in the SMA100 management interface to prevent command injection attacks.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

4.18%
Probability of exploitation in next 30 days
90.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE