CVE-2021-20016

CVE Published 2021-02-04
Related CWE(s) CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Related Vendor(s) sonicwall
Related Product(s) sma_500v, sma_400_firmware, sma_410_firmware, sma_100_firmware, sma_200_firmware, sma_210_firmware
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References