peter bassill · operator
$ cve CVE-2021-20035 JSON

CVE-2021-20035 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 4.2% (pctl 91)

Patch first

On CISA KEV — known exploited in the wild, due 2025-05-07.

Description

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS4.18% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2025-05-07
Public exploitnone known
Published2021-09-27
Last modified2026-06-17

CISA KEV

NameSonicWall SMA100 Appliances OS Command Injection Vulnerability
Added2025-04-16
Due2025-05-07
Vendor / productSonicWall / SMA100 Appliances
Ransomware usenone reported

Affected (9)

VendorProduct
sonicwallsma 200
sonicwallsma 200 firmware
sonicwallsma 210
sonicwallsma 210 firmware
sonicwallsma 400
sonicwallsma 400 firmware
sonicwallsma 410
sonicwallsma 410 firmware
sonicwallsma 500v

References

→ the Explorer  ·  watch your stack  ·  NVD