PT-2021-13740 · Sonicwall · Sonicwall Sma210+5

Published

2021-12-08

·

Updated

2021-12-10

·

CVE-2021-20044

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SonicWall SMA100 versions (affected versions not specified) SonicWall SMA200 SonicWall SMA210 SonicWall SMA400 SonicWall SMA410 SonicWall SMA500v
Description: A post-authentication remote command injection issue allows a remote authenticated attacker to execute OS system commands in the appliance.
Recommendations: For SonicWall SMA100, update to a version that fixes the remote command injection vulnerability. For SonicWall SMA200, update to a version that fixes the remote command injection vulnerability. For SonicWall SMA210, update to a version that fixes the remote command injection vulnerability. For SonicWall SMA400, update to a version that fixes the remote command injection vulnerability. For SonicWall SMA410, update to a version that fixes the remote command injection vulnerability. For SonicWall SMA500v, update to a version that fixes the remote command injection vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20044

Affected Products

Sonicwall Sma100
Sonicwall Sma200
Sonicwall Sma210
Sonicwall Sma400
Sonicwall Sma410
Sonicwall Sma500V