CVE-2021-20016KEV · OVERDUECWE-89sql-injection

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

Critical · published February 4, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 98.5th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
40%
Percentile
98.5
In the wild
Confirmed
What it is

🚨 A SQL injection vulnerability in SonicWall’s SSLVPN SMA100 could hand over user passwords and session data to remote attackers — and the best part? They don’t even need to be logged in! 🔥 Think of it like a restaurant where the waiter trusts any customer who orders food without checking their ID — they could walk into the kitchen and steal the secret recipes! If exploited, an attacker could access sensitive usernames and passwords, compromising entire accounts and potentially leading to unauthorized access across systems. This could be absolutely devastating for anyone relying on this product, as their sensitive information could be at risk. 😱

Put simply

Think of it like a restaurant where the waiter trusts any customer who orders food without checking their ID — they could walk into the kitchen and steal the secret recipes! This vulnerability allows remote unauthenticated attackers to perform malicious SQL queries against the SMA100 product, compromising user sessions and sensitive data.

What to do

If exploited, an attacker could access sensitive usernames and passwords, compromising entire accounts and potentially leading to unauthorized access across systems. This could be absolutely devastating for anyone relying on this product, as their sensitive information could be at risk. 😱 Immediate action is necessary! Patch your SonicWall SSLVPN to the latest version available to close this vulnerability. Verify your network configuration and consider implementing additional security measures to prevent unauthorized access. 🛡️ You’ve got this! Stay vigilant and secure your systems, and you’ll help keep the internet a safer place! 💪

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.40038 · 98.5th percentile
Weakness
CWE-89 · Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Published
2021-02-04T11:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (6)
ProductVersionsFixed in
sonicwall/sma_100_firmware≥ 10.0.0.0, < 10.2.0.5-d-29sv10.2.0.5-d-29sv
sonicwall/sma_200_firmwareall versions
sonicwall/sma_210_firmwareall versions
sonicwall/sma_400_firmwareall versions
sonicwall/sma_410_firmwareall versions
sonicwall/sma_500vall versions
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 03 FEB 20:35Z
    A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password…
    cvelistv5