CVE-2021-20042 PUBLISHED CVSS 7.5 HIGH

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

EPSS 0.88% · 75.3th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
0.88%
75.3th percentile

Affected Products

VendorProductVersions
sonicwallsma_500v_firmware10.2.1.1-19sv, 10.2.0.8-37sv, 9.0.0.11-31sv
SonicWallSonicWall SMA10010.2.1.2-24sv and earlier, 9.0.0.11-31sv and earlier, 10.2.0.8-37sv and earlier
sonicwallsma_410_firmware9.0.0.11-31sv, 10.2.0.8-37sv, 10.2.1.1-19sv
sonicwallsma_400_firmware9.0.0.11-31sv, 10.2.0.8-37sv, 10.2.1.1-19sv
sonicwallsma_210_firmware9.0.0.11-31sv, 10.2.0.8-37sv, 10.2.1.1-19sv
sonicwallsma_200_firmware10.2.1.1-19sv, 10.2.0.8-37sv, 9.0.0.11-31sv

Timeline

References

Open in Interactive Console →