CVE-2021-20028
KEV ransomwaremoderateSQL Injection in SonicWall Secure Remote Access (SRA) Appliances
CISA: SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
CVE-2021-20028 is a SQL injection flaw (CWE-89) in SonicWall's Secure Remote Access (SRA) appliances, caused by improper neutralization of SQL commands processed by the device. An attacker who sends crafted input to the appliance's web-facing interface can inject SQL and read or manipulate the backend database, potentially extracting credentials or gaining a foothold on the gateway. Any organization still running the legacy, end-of-life SonicWall SRA remote-access product line is affected, and because these devices are remote-access gateways they are typically internet-exposed by design. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, and EPSS assigns a 29.9% probability of exploitation in the next 30 days (98th percentile). No public proof-of-concept is known, no CVSS score has been published, and the source data does not specify affected firmware versions.
What to do: Because CISA lists the impacted product as end-of-life with the required action to disconnect it, any organization still running an SRA appliance should decommission it and migrate to a supported SonicWall Secure Mobile Access (SMA) platform. If immediate replacement is not possible, restrict exposure of the appliance's web interface, apply the latest available SRA firmware if one is offered, and review logs for signs of SQL injection exploitation or follow-on ransomware activity.
| SonicWall Secure Remote Access (SRA) series appliances | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
- Affected
- SonicWall Secure Remote Access (SRA)
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Known
- Vendors
- sonicwall
- Products
- sma 210 firmware, sma 410 firmware, sma 500v firmware, sra 4600 firmware, sra 1600 firmware, sra va firmware
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H