ZeroHour

CVE-2021-20038

KEV ransomware PoC ×2large

Unauthenticated Stack Buffer Overflow in SonicWall SMA 100 Appliances

CISA: SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

SonicWall SMA 100 series secure remote-access appliances contain an unauthenticated stack-based buffer overflow (CWE-121) in the appliance's network-facing interface, triggered by crafted requests sent to the device without any credentials. A remote attacker who triggers the overflow can execute arbitrary code on the appliance with the privileges of the affected service, gaining a foothold on an internet-facing VPN gateway that typically sits at the network edge. Any organization running an SMA 100 series appliance is affected, and because these appliances provide remote access to corporate networks, compromise can expose entire internal environments. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-01-28 with known ransomware use, and EPSS assigns a 99.9% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is catalogued in the provided data, but the KEV listing and EPSS score indicate active attacker interest.

What to do: Upgrade SMA 100 series appliances to firmware 10.0.7.2 or later per SonicWall's instructions, as required by the CISA KEV listing. Until patched, restrict internet exposure of the SMA portal and management interface to trusted sources where feasible. Because ransomware operators are known to exploit this flaw, review appliance logs for signs of compromise and monitor for unexpected account creation or traffic after patching.

Affected
SonicWall SMA 100 AppliancesPer SonicWall's advisory, SMA 100 series firmware 10.0.7.1 and earlier (fixed in 10.0.7.2 and later); the CISA record does not specify version ranges, so admini
Estimated exposure
largetens of thousands of internet-exposed SMA 100 appliances (order of magnitude ~10,000-50,000 devices), plus a larger installed base used internally — SMA 100 appliances are widely deployed by small and mid-sized organizations as remote-access gateways, and public internet scans (Shodan/Censys) have historically shown on the order of tens of thousands of SonicWall SMA/SSL-VPN devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

CISA Known Exploited Vulnerability
Affected
SonicWall SMA 100 Appliances
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
sma 200 firmware, sma 210 firmware, sma 410 firmware, sma 400 firmware, sma 500v firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news