Sonicwall
Sonicwall SMA 500v: vulnerabilities and CVEs
Sonicwall SMA 500v has 3 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 2 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical2
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20035 | Medium (6.5) | 4.2% | ⚠ Active exploitation | Sep 27, 2021 | Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS. |
| CVE-2021-20016 | Critical (9.8) | 40% | ⚠ Active exploitation | Feb 4, 2021 | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20035 | Medium (6.5) | 4.2% | ⚠ Active exploitation | Sep 27, 2021 | Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS. |
| CVE-2021-20034 | Critical (9.1) | 81% | — | Sep 27, 2021 | An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. |
| CVE-2021-20016 | Critical (9.8) | 40% | ⚠ Active exploitation | Feb 4, 2021 | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.