ZeroHour

CVE-2021-20040

CVSS 3.1
7.5 high
EPSS
25%p98
Published
()
Modified
Description

A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

Vendors
sonicwall
Products
sma 200 firmware, sma 210 firmware, sma 410 firmware, sma 400 firmware, sma 500v firmware
Weakness
CWE-23, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news