VDB

CVE-2021-20040

CVE-2021-20040 PUBLISHED CVSS 7.5 HIGH

A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

EPSS 8.81% · 92.7th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
8.81%
92.7th percentile

Affected Products

VendorProductVersions
sonicwallsma_410_firmware10.2.0.8-37sv, 10.2.1.1-19sv
sonicwallsma_200_firmware10.2.0.8-37sv, 10.2.1.1-19sv
sonicwallsma_500v_firmware10.2.1.1-19sv, 10.2.0.8-37sv
sonicwallsma_400_firmware10.2.0.8-37sv, 10.2.1.1-19sv
sonicwallsma_210_firmware10.2.0.8-37sv, 10.2.1.1-19sv
SonicWallSonicWall SMA10010.2.0.8-37sv and earlier, 10.2.1.1-19sv and earlier, 10.2.1.2-24sv and earlier

Timeline

  • Dec 8, 2021 CVE Published
  • Dec 9, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 12, 2022 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 28, 2022 EPSS Score
  • May 22, 2022 EPSS Score
  • Jul 16, 2022 EPSS Score
  • Sep 9, 2022 EPSS Score
  • Dec 27, 2022 EPSS Score
  • Feb 19, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›