Vulnerabilities
Vulnerable Software
Sonicwall:  >> Sma 500v Firmware  Security Vulnerabilities
CVE-2021-20038
Known exploited
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.
CVSS Score
9.8
EPSS Score
0.943
Published
2021-12-08
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
CVSS Score
8.8
EPSS Score
0.615
Published
2021-12-08
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
CVSS Score
7.5
EPSS Score
0.063
Published
2021-12-08
CVE-2021-20028
Known exploited
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
CVSS Score
9.8
EPSS Score
0.867
Published
2021-08-04


Contact Us

Shodan ® - All rights reserved