peter bassill · operator
$ cve CVE-2021-20016 JSON

CVE-2021-20016 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 40% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2021-11-17.

Description

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS40.04% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVyes — remediate by 2021-11-17
Public exploitnone known
Published2021-02-04
Last modified2026-08-12

CISA KEV

NameSonicWall SSLVPN SMA100 SQL Injection Vulnerability
Added2021-11-03
Due2021-11-17
Vendor / productSonicWall / SSLVPN SMA100
Ransomware useknown

Affected (11)

VendorProduct
sonicwallsma 100
sonicwallsma 100 firmware
sonicwallsma 200
sonicwallsma 200 firmware
sonicwallsma 210
sonicwallsma 210 firmware
sonicwallsma 400
sonicwallsma 400 firmware
sonicwallsma 410
sonicwallsma 410 firmware
sonicwallsma 500v

References

→ the Explorer  ·  watch your stack  ·  NVD