CVE-2021-20049
23.12.2021, 02:15
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.Enginsight
Vendor | Product | Version |
---|---|---|
sonicwall | sma_100_firmware | 𝑥 < 10.0.0.0 |
sonicwall | sma_100_firmware | 10.2.0.8-37sv |
sonicwall | sma_100_firmware | 10.2.1.2-24sv |
sonicwall | sma_200_firmware | 𝑥 < 10.0.0.0 |
sonicwall | sma_200_firmware | 10.2.0.8-37sv |
sonicwall | sma_200_firmware | 10.2.1.2-24sv |
sonicwall | sma_210_firmware | 𝑥 < 10.0.0.0 |
sonicwall | sma_210_firmware | 10.2.0.8-37sv |
sonicwall | sma_210_firmware | 10.2.1.2-24sv |
sonicwall | sma_400_firmware | 𝑥 < 10.0.0.0 |
sonicwall | sma_400_firmware | 10.2.0.8-37sv |
sonicwall | sma_400_firmware | 10.2.1.2-24sv |
sonicwall | sma_410_firmware | 𝑥 < 10.0.0.0 |
sonicwall | sma_410_firmware | 10.2.0.8-37sv |
sonicwall | sma_410_firmware | 10.2.1.2-24sv |
sonicwall | sma_500v_firmware | 𝑥 < 10.0.0.0 |
sonicwall | sma_500v_firmware | 10.2.0.8-37sv |
sonicwall | sma_500v_firmware | 10.2.1.2-24sv |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-204 - Observable Response DiscrepancyThe product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
- CWE-203 - Observable DiscrepancyThe product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.