CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
89.9%
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
Vendor | Product | Version | CPE |
---|---|---|---|
sonicwall | sma_210_firmware | * | cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:* |
sonicwall | sma_210 | - | cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:* |
sonicwall | sma_410_firmware | * | cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:* |
sonicwall | sma_410 | - | cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:* |
sonicwall | sma_500v_firmware | * | cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:* |
sonicwall | sma_500v | - | cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:* |
sonicwall | sra_4600_firmware | * | cpe:2.3:o:sonicwall:sra_4600_firmware:*:*:*:*:*:*:*:* |
sonicwall | sra_4600 | - | cpe:2.3:h:sonicwall:sra_4600:-:*:*:*:*:*:*:* |
sonicwall | sra_1600_firmware | * | cpe:2.3:o:sonicwall:sra_1600_firmware:*:*:*:*:*:*:*:* |
sonicwall | sra_1600 | - | cpe:2.3:h:sonicwall:sra_1600:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
89.9%