ZeroHour

CVE-2021-20016

KEV ransomwarelarge1

Unauthenticated SQL Injection in SonicWall SMA100 SSL VPN

CISA: SonicWall SSLVPN SMA100 SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
40%p99
Published
()
KEV added
AI analysis

CVE-2021-20016 is an unauthenticated SQL injection flaw (CWE-89) in the SonicWall SSL-VPN service on SMA 100 appliances. It is triggered remotely by malicious, unauthenticated requests to the appliance's web interface, allowing SQL injection against the backend database. Successful exploitation gives the attacker credential access — harvesting valid user credentials that can then be used to log into the SSL-VPN and pivot into the victim network. Any organization running an internet-facing SonicWall SSLVPN SMA100 appliance is affected, and CISA notes known ransomware use of this flaw. It was added to the CISA Known Exploited Vulnerabilities catalog on 2021-11-03 and carries a 40% EPSS probability of exploitation within 30 days (99th percentile), so it should be treated as actively exploited even though no public proof-of-concept is known.

What to do: Apply the SonicWall firmware update per vendor instructions, as required by the CISA KEV listing. Because ransomware operators are known to exploit this flaw, review SMA100 authentication and admin logs for unfamiliar logins, rotate exposed credentials, and restrict the appliance to trusted source IPs until it is patched. CVSS has not yet been scored, but the 40% EPSS (99th percentile) and KEV status warrant immediate patching of all internet-exposed units.

Affected
SonicWall SSLVPN SMA100
Estimated exposure
large≈ tens of thousands of internet-exposed SMA100 appliances (public scan counts of SonicWall SSL-VPN endpoints) — SMA 100-series appliances are typically deployed as internet-facing SSL-VPN gateways by small and mid-sized organizations, and public internet-wide scans of SonicWall SSL-VPN endpoints have consistently counted reachable devices in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

CISA Known Exploited Vulnerability
Affected
SonicWall SSLVPN SMA100
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
sma 100 firmware, sma 200 firmware, sma 210 firmware, sma 400 firmware, sma 410 firmware, sma 500v
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news