TROYANOSYVIRUS
Volver a CVEs

CVE-2021-20016

CRITICALCISA KEV
9.8

Descripcion

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado2/4/2021
Ultima modificacion10/31/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorSonicWall
ProductoSSLVPN SMA100
Nombre vulnerabilidadSonicWall SSLVPN SMA100 SQL Injection Vulnerability
Fecha inclusion KEV2021-11-03
Fecha limite remediacion2021-11-17
Uso en ransomwareKnown

Productos afectados

sonicwall:sma_100sonicwall:sma_100_firmwaresonicwall:sma_200sonicwall:sma_200_firmwaresonicwall:sma_210sonicwall:sma_210_firmwaresonicwall:sma_400sonicwall:sma_400_firmwaresonicwall:sma_410sonicwall:sma_410_firmwaresonicwall:sma_500v

Debilidades (CWE)

CWE-89CWE-89

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.