CVE-2021-20035
27.09.2021, 18:15
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Vendor | Product | Version |
---|---|---|
sonicwall | sma_200_firmware | 𝑥 < 9.0.0.11-31sv |
sonicwall | sma_200_firmware | 10.2.0.0 ≤ 𝑥 < 10.2.0.8-37sv |
sonicwall | sma_200_firmware | 10.2.1.0 ≤ 𝑥 < 10.2.1.1-19sv |
sonicwall | sma_210_firmware | 𝑥 < 9.0.0.11-31sv |
sonicwall | sma_210_firmware | 10.2.0.0 ≤ 𝑥 < 10.2.0.8-37sv |
sonicwall | sma_210_firmware | 10.2.1.0 ≤ 𝑥 < 10.2.1.1-19sv |
sonicwall | sma_400_firmware | 𝑥 < 9.0.0.11-31sv |
sonicwall | sma_400_firmware | 10.2.0.0 ≤ 𝑥 < 10.2.0.8-37sv |
sonicwall | sma_400_firmware | 10.2.1.0 ≤ 𝑥 < 10.2.1.1-19sv |
sonicwall | sma_410_firmware | 𝑥 < 9.0.0.11-31sv |
sonicwall | sma_410_firmware | 10.2.0.0 ≤ 𝑥 < 10.2.0.8-37sv |
sonicwall | sma_410_firmware | 10.2.1.0 ≤ 𝑥 < 10.2.1.1-19sv |
sonicwall | sma_500v | 𝑥 < 9.0.0.11-31sv |
sonicwall | sma_500v | 10.2.0.0 ≤ 𝑥 < 10.2.0.8-37sv |
sonicwall | sma_500v | 10.2.1.0 ≤ 𝑥 < 10.2.1.1-19sv |
𝑥
= Vulnerable software versions