Description
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Related CPE's
o
sonicwall
sma_200_firmware
3
o
sonicwall
sma_210_firmware
3
o
sonicwall
sma_400_firmware
3
o
sonicwall
sma_410_firmware
3
a
sonicwall
sma_500v
3
References
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20035
US Government Resource
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
6.5 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2021-09-27T16:15:08.383Z
4 years agoLast modified
2025-10-31T16:13:28.377Z
4 months ago