« Volver al listado

CVE-2021-20019

Estado: ModificadaAlta (7.5)—

A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20019",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "PSIRT@sonicwall.com",
      "affectedData": [
        {
          "vendor": "SonicWall",
          "product": "SonicOS",
          "versions": [
            {
              "status": "affected",
              "version": "SonicOS - 6.5.4.7-83n"
            },
            {
              "status": "affected",
              "version": "SonicOSv - 6.5.4.4-44v-21-955"
            },
            {
              "status": "affected",
              "version": "SonicOS - 6.5.1.12-3n"
            },
            {
              "status": "affected",
              "version": "SonicOS - 6.0.5.3-94o"
            },
            {
              "status": "affected",
              "version": "SonicOS - 7.0.0-R713 and earlier"
            },
            {
              "status": "affected",
              "version": "SonicOS - 7.0.1-R1036 and earlier"
            },
            {
              "status": "affected",
              "version": "SonicOS - 7.0.0.375 and earlier"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-06-23T22:15:08.323",
  "references": [
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0006",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "PSIRT@sonicwall.com"
    },
    {
      "url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0006",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "PSIRT@sonicwall.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in SonicOS where the HTTP server response leaks partial memory by sending a crafted HTTP request, this can potentially lead to an internal sensitive data disclosure vulnerability."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en SonicOS donde la respuesta del servidor HTTP filtra parte de la memoria mediante el envío de una petición HTTP diseñada, esto puede conllevar potencialmente a una vulnerabilidad de divulgación de datos confidenciales internos"
    }
  ],
  "lastModified": "2026-06-17T03:33:09.223",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D42B9BB-66D4-4389-8F91-91148E2A6B9B",
              "versionEndExcluding": "7.0.0.376",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15CCFEA2-9302-4BEB-A5E3-9F6CE47A7FF6",
              "versionEndExcluding": "7.0.1-r1036",
              "versionStartIncluding": "7.0.1"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sonicos:6.0.5.3-94o:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BC37D8B-1946-4998-AA64-A03D226CAA27"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sonicos:6.5.1.12-3n:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "509A9DBE-EC4B-45B3-BB09-3E0C141180B7"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sonicos:6.5.4.7-83n:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CCE0644-D540-459E-AD53-698F12D08B94"
            },
            {
              "criteria": "cpe:2.3:o:sonicwall:sonicosv:6.5.4.4-44v-21-955:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F2140596-2050-4CE1-8DB0-04F2A478955A"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "PSIRT@sonicwall.com"
}