CVE-2021-20039 PUBLISHED CVSS 9 CRITICAL

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

EPSS 82.46% · 99.2th percentile

Risk Scores

CVSS v2.0
9
EPSS Score
82.46%
99.2th percentile

Affected Products

VendorProductVersions
sonicwallsma_200_firmware10.2.1.1-19sv, 9.0.0.11-31sv, 10.2.0.8-37sv
sonicwallsma_400_firmware10.2.0.8-37sv, 10.2.1.1-19sv, 9.0.0.11-31sv
sonicwallsma_210_firmware10.2.0.8-37sv, 9.0.0.11-31sv, 10.2.1.1-19sv
sonicwallsma_410_firmware10.2.1.1-19sv, 10.2.0.8-37sv, 9.0.0.11-31sv
sonicwallsma_500v_firmware10.2.0.8-37sv, 10.2.1.1-19sv, 9.0.0.11-31sv
SonicWallSonicWall SMA10010.2.0.8-37sv and earlier, 9.0.0.11-31sv and earlier, 10.2.1.2-24sv and earlier

Timeline

References

Open in Interactive Console →