« Back to list

Sonicwall

Sonicwall SMA 500v: vulnerabilities and CVEs

Sonicwall SMA 500v has 3 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 2 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical2
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-20035Medium (6.5)4.2%⚠ Active exploitationSep 27, 2021
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
CVE-2021-20016Critical (9.8)40%⚠ Active exploitationFeb 4, 2021
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2021-20035Medium (6.5)4.2%⚠ Active exploitationSep 27, 2021
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
CVE-2021-20034Critical (9.1)81%—Sep 27, 2021
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
CVE-2021-20016Critical (9.8)40%⚠ Active exploitationFeb 4, 2021
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1059 Command and Scripting Interpreter1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Sonicwall