CVE-2021-20016
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
CVSS
9.8
Crítico
EPSS
40.0%
p99
KEV
SÍ
3 nov 2021
Exploit Today
80
0-100
Publicado: 4 feb 2021 · Última mod.: 12 ago 2026 · CWE-89
Producto
SonicWall / SSLVPN SMA100
Vulnerabilidad
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
Añadido a KEV
3 nov 2021
Remediar antes de
17 nov 2021
Uso conocido en ransomware
Sí
Descripción resumida
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
Acción requerida
Apply updates per vendor instructions.
Notas
https://nvd.nist.gov/vuln/detail/CVE-2021-20016
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.