ZeroHour

CVE-2021-20039

PoC
CVSS 3.1
8.8 high
EPSS
79%p100
Published
()
Modified
Description

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

Vendors
sonicwall
Products
sma 200 firmware, sma 210 firmware, sma 410 firmware, sma 400 firmware, sma 500v firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news