CVE-2021-20016
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
CVSS
9.8
Critical
EPSS
40.0%
p99
KEV
YES
Nov 3, 2021
Exploit Today
80
0-100
Published: Feb 4, 2021 · Last modified: Aug 12, 2026 · CWE-89
Product
SonicWall / SSLVPN SMA100
Vulnerability
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
Added to KEV
Nov 3, 2021
Remediate by
Nov 17, 2021
Known ransomware use
Yes
Summary description
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-20016
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.