CVE-2021-20042
9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.68% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-441 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-12-08 |
| Last modified | 2026-06-17 |
Affected (10)
| Vendor | Product |
|---|---|
| sonicwall | sma 200 |
| sonicwall | sma 200 firmware |
| sonicwall | sma 210 |
| sonicwall | sma 210 firmware |
| sonicwall | sma 400 |
| sonicwall | sma 400 firmware |
| sonicwall | sma 410 |
| sonicwall | sma 410 firmware |
| sonicwall | sma 500v |
| sonicwall | sma 500v firmware |
References
→ the Explorer · watch your stack · NVD