Lucene search

K
cvelistSonicwallCVELIST:CVE-2021-20039
HistoryDec 08, 2021 - 9:55 a.m.

CVE-2021-20039

2021-12-0809:55:21
CWE-78
sonicwall
www.cve.org
7
vulnerability
sma100
remote command injection
cve-2021-20039
http
sma 200
sma 210
sma 400
sma 410
sma 500v

AI Score

9.3

Confidence

High

EPSS

0.677

Percentile

98.0%

Improper neutralization of special elements in the SMA100 management interface ‘/cgi-bin/viewcert’ POST http method allows a remote authenticated attacker to inject arbitrary commands as a ‘nobody’ user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

CNA Affected

[
  {
    "product": "SonicWall SMA100",
    "vendor": "SonicWall",
    "versions": [
      {
        "status": "affected",
        "version": "9.0.0.11-31sv and earlier"
      },
      {
        "status": "affected",
        "version": "10.2.0.8-37sv and earlier"
      },
      {
        "status": "affected",
        "version": "10.2.1.1-19sv and earlier"
      },
      {
        "status": "affected",
        "version": "10.2.1.2-24sv and earlier"
      }
    ]
  }
]