PT-2021-4029 · Sonicwall · Sonicwall Nsm On-Prem

Nikita Abramov

·

Published

2021-05-27

·

Updated

2021-06-08

·

CVE-2021-20026

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SonicWall NSM On-Prem versions 2.2.0-R10 and earlier
Description A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. The issue is related to the failure to neutralize special elements used in an OS command. This could allow a remote attacker to execute arbitrary commands using specially crafted HTTP requests.
Recommendations For versions 2.2.0-R10 and earlier, update to a version later than 2.2.0-R10 to resolve the issue. As a temporary workaround, consider restricting access to the HTTP request functionality to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04556
CVE-2021-20026

Affected Products

Sonicwall Nsm On-Prem