Vulnerability Details CVE-2021-20035
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.14
EPSS Ranking 94.0%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.8
Proposed Action
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.
Ransomware Campaign
Unknown
Products affected by CVE-2021-20035
-
cpe:2.3:a:sonicwall:sma_500v:-
-
cpe:2.3:a:sonicwall:sma_500v:10.2.0.0
-
cpe:2.3:a:sonicwall:sma_500v:10.2.0.7-34sv
-
cpe:2.3:a:sonicwall:sma_500v:10.2.1.0
-
cpe:2.3:a:sonicwall:sma_500v:10.2.1.0-17sv
-
cpe:2.3:a:sonicwall:sma_500v:9.0.0.10-28sv
-
cpe:2.3:h:sonicwall:sma_200:-
-
cpe:2.3:h:sonicwall:sma_210:-
-
cpe:2.3:h:sonicwall:sma_400:-
-
cpe:2.3:h:sonicwall:sma_410:-
-
cpe:2.3:o:sonicwall:sma_200_firmware:-
-
cpe:2.3:o:sonicwall:sma_200_firmware:10.2.0.0
-
cpe:2.3:o:sonicwall:sma_200_firmware:10.2.0.7-34sv
-
cpe:2.3:o:sonicwall:sma_200_firmware:10.2.1.0
-
cpe:2.3:o:sonicwall:sma_200_firmware:10.2.1.0-17sv
-
cpe:2.3:o:sonicwall:sma_200_firmware:9.0.0.10-28sv
-
cpe:2.3:o:sonicwall:sma_210_firmware:-
-
cpe:2.3:o:sonicwall:sma_210_firmware:10.2.0.0
-
cpe:2.3:o:sonicwall:sma_210_firmware:10.2.0.7-34sv
-
cpe:2.3:o:sonicwall:sma_210_firmware:10.2.1.0
-
cpe:2.3:o:sonicwall:sma_210_firmware:10.2.1.0-17sv
-
cpe:2.3:o:sonicwall:sma_210_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_210_firmware:9.0.0.10
-
cpe:2.3:o:sonicwall:sma_210_firmware:9.0.0.10-28sv
-
cpe:2.3:o:sonicwall:sma_400_firmware:-
-
cpe:2.3:o:sonicwall:sma_400_firmware:10.2.0.0
-
cpe:2.3:o:sonicwall:sma_400_firmware:10.2.0.7-34sv
-
cpe:2.3:o:sonicwall:sma_400_firmware:10.2.1.0
-
cpe:2.3:o:sonicwall:sma_400_firmware:10.2.1.0-17sv
-
cpe:2.3:o:sonicwall:sma_400_firmware:9.0.0.10-28sv
-
cpe:2.3:o:sonicwall:sma_410_firmware:-
-
cpe:2.3:o:sonicwall:sma_410_firmware:10.2.0.0
-
cpe:2.3:o:sonicwall:sma_410_firmware:10.2.0.7-34sv
-
cpe:2.3:o:sonicwall:sma_410_firmware:10.2.1.0
-
cpe:2.3:o:sonicwall:sma_410_firmware:10.2.1.0-17sv
-
cpe:2.3:o:sonicwall:sma_410_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_410_firmware:9.0.0.10
-
cpe:2.3:o:sonicwall:sma_410_firmware:9.0.0.10-28sv