// For flags

CVE-2021-20028

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

Una neutralización inapropiada de un Comando SQL conllevando una vulnerabilidad de Inyección SQL impactando a los productos Secure Remote Access (SRA) al final de su vida útil, concretamente a dispositivos SRA que ejecutan todo el firmware 8.x y 9.0.0.9-26sv o anteriores

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-08-04 CVE Published
  • 2022-03-28 Exploited in Wild
  • 2022-04-18 KEV Due Date
  • 2024-04-19 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- First Exploit
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sonicwall
Search vendor "Sonicwall"
Sma 210 Firmware
Search vendor "Sonicwall" for product "Sma 210 Firmware"
>= 8.0.0.0 < 9.0.0.10
Search vendor "Sonicwall" for product "Sma 210 Firmware" and version " >= 8.0.0.0 < 9.0.0.10"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma 210
Search vendor "Sonicwall" for product "Sma 210"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 410 Firmware
Search vendor "Sonicwall" for product "Sma 410 Firmware"
>= 8.0.0.0 < 9.0.0.10
Search vendor "Sonicwall" for product "Sma 410 Firmware" and version " >= 8.0.0.0 < 9.0.0.10"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma 410
Search vendor "Sonicwall" for product "Sma 410"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 500v Firmware
Search vendor "Sonicwall" for product "Sma 500v Firmware"
>= 8.0.0.0 < 9.0.0.10
Search vendor "Sonicwall" for product "Sma 500v Firmware" and version " >= 8.0.0.0 < 9.0.0.10"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma 500v
Search vendor "Sonicwall" for product "Sma 500v"
--
Safe
* End Of Life in some or all products. Do not expect updates.