ZeroHour

CVE-2021-20028

KEV ransomwaremoderate

SQL Injection in SonicWall Secure Remote Access (SRA) Appliances

CISA: SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
30%p98
Published
()
KEV added
AI analysis

CVE-2021-20028 is a SQL injection flaw (CWE-89) in SonicWall's Secure Remote Access (SRA) appliances, caused by improper neutralization of SQL commands processed by the device. An attacker who sends crafted input to the appliance's web-facing interface can inject SQL and read or manipulate the backend database, potentially extracting credentials or gaining a foothold on the gateway. Any organization still running the legacy, end-of-life SonicWall SRA remote-access product line is affected, and because these devices are remote-access gateways they are typically internet-exposed by design. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and EPSS assigns a 29.9% probability of exploitation in the next 30 days (98th percentile). No public proof-of-concept is known, no CVSS score has been published, and the source data does not specify affected firmware versions.

What to do: Because CISA lists the impacted product as end-of-life with the required action to disconnect it, any organization still running an SRA appliance should decommission it and migrate to a supported SonicWall Secure Mobile Access (SMA) platform. If immediate replacement is not possible, restrict exposure of the appliance's web interface, apply the latest available SRA firmware if one is offered, and review logs for signs of SQL injection exploitation or follow-on ransomware activity.

Affected
SonicWall Secure Remote Access (SRA) series appliances
Estimated exposure
moderate≈ several thousand legacy, internet-facing SRA appliances worldwide — Estimate based on deployment patterns: SonicWall SRA remote-access gateways must be internet-facing to function, but the product line is end-of-life so the remaining in-use installed base is plausibly in the low thousands of devices; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

CISA Known Exploited Vulnerability
Affected
SonicWall Secure Remote Access (SRA)
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
sma 210 firmware, sma 410 firmware, sma 500v firmware, sra 4600 firmware, sra 1600 firmware, sra va firmware
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news