// For flags

CVE-2021-20049

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.

Una vulnerabilidad en la API de cambio de contraseña de SonicWall SMA100, permite a un atacante remoto no autenticado llevar a cabo una enumeración de nombres de usuario de SMA100 basándose en las respuestas del servidor. Esta vulnerabilidad afecta a las versiones 10.2.1.2-24sv, 10.2.0.8-37sv y versiones anteriores 10.x

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-12-23 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-09-07 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-203: Observable Discrepancy
  • CWE-204: Observable Response Discrepancy
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sonicwall
Search vendor "Sonicwall"
Sma 100 Firmware
Search vendor "Sonicwall" for product "Sma 100 Firmware"
< 10.0.0.0
Search vendor "Sonicwall" for product "Sma 100 Firmware" and version " < 10.0.0.0"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma100
Search vendor "Sonicwall" for product "Sma100"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 100 Firmware
Search vendor "Sonicwall" for product "Sma 100 Firmware"
10.2.0.8-37sv
Search vendor "Sonicwall" for product "Sma 100 Firmware" and version "10.2.0.8-37sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma100
Search vendor "Sonicwall" for product "Sma100"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 100 Firmware
Search vendor "Sonicwall" for product "Sma 100 Firmware"
10.2.1.2-24sv
Search vendor "Sonicwall" for product "Sma 100 Firmware" and version "10.2.1.2-24sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma100
Search vendor "Sonicwall" for product "Sma100"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 200 Firmware
Search vendor "Sonicwall" for product "Sma 200 Firmware"
< 10.0.0.0
Search vendor "Sonicwall" for product "Sma 200 Firmware" and version " < 10.0.0.0"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma200
Search vendor "Sonicwall" for product "Sma200"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 200 Firmware
Search vendor "Sonicwall" for product "Sma 200 Firmware"
10.2.0.8-37sv
Search vendor "Sonicwall" for product "Sma 200 Firmware" and version "10.2.0.8-37sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma200
Search vendor "Sonicwall" for product "Sma200"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 200 Firmware
Search vendor "Sonicwall" for product "Sma 200 Firmware"
10.2.1.2-24sv
Search vendor "Sonicwall" for product "Sma 200 Firmware" and version "10.2.1.2-24sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma200
Search vendor "Sonicwall" for product "Sma200"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 210 Firmware
Search vendor "Sonicwall" for product "Sma 210 Firmware"
< 10.0.0.0
Search vendor "Sonicwall" for product "Sma 210 Firmware" and version " < 10.0.0.0"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma210
Search vendor "Sonicwall" for product "Sma210"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 210 Firmware
Search vendor "Sonicwall" for product "Sma 210 Firmware"
10.2.0.8-37sv
Search vendor "Sonicwall" for product "Sma 210 Firmware" and version "10.2.0.8-37sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma210
Search vendor "Sonicwall" for product "Sma210"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 210 Firmware
Search vendor "Sonicwall" for product "Sma 210 Firmware"
10.2.1.2-24sv
Search vendor "Sonicwall" for product "Sma 210 Firmware" and version "10.2.1.2-24sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma210
Search vendor "Sonicwall" for product "Sma210"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 400 Firmware
Search vendor "Sonicwall" for product "Sma 400 Firmware"
< 10.0.0.0
Search vendor "Sonicwall" for product "Sma 400 Firmware" and version " < 10.0.0.0"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma400
Search vendor "Sonicwall" for product "Sma400"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 400 Firmware
Search vendor "Sonicwall" for product "Sma 400 Firmware"
10.2.0.8-37sv
Search vendor "Sonicwall" for product "Sma 400 Firmware" and version "10.2.0.8-37sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma400
Search vendor "Sonicwall" for product "Sma400"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 400 Firmware
Search vendor "Sonicwall" for product "Sma 400 Firmware"
10.2.1.2-24sv
Search vendor "Sonicwall" for product "Sma 400 Firmware" and version "10.2.1.2-24sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma400
Search vendor "Sonicwall" for product "Sma400"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 410 Firmware
Search vendor "Sonicwall" for product "Sma 410 Firmware"
< 10.0.0.0
Search vendor "Sonicwall" for product "Sma 410 Firmware" and version " < 10.0.0.0"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma410
Search vendor "Sonicwall" for product "Sma410"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 410 Firmware
Search vendor "Sonicwall" for product "Sma 410 Firmware"
10.2.0.8-37sv
Search vendor "Sonicwall" for product "Sma 410 Firmware" and version "10.2.0.8-37sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma410
Search vendor "Sonicwall" for product "Sma410"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 410 Firmware
Search vendor "Sonicwall" for product "Sma 410 Firmware"
10.2.1.2-24sv
Search vendor "Sonicwall" for product "Sma 410 Firmware" and version "10.2.1.2-24sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma410
Search vendor "Sonicwall" for product "Sma410"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 500v Firmware
Search vendor "Sonicwall" for product "Sma 500v Firmware"
< 10.0.0.0
Search vendor "Sonicwall" for product "Sma 500v Firmware" and version " < 10.0.0.0"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma500v
Search vendor "Sonicwall" for product "Sma500v"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 500v Firmware
Search vendor "Sonicwall" for product "Sma 500v Firmware"
10.2.0.8-37sv
Search vendor "Sonicwall" for product "Sma 500v Firmware" and version "10.2.0.8-37sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma500v
Search vendor "Sonicwall" for product "Sma500v"
--
Safe
Sonicwall
Search vendor "Sonicwall"
Sma 500v Firmware
Search vendor "Sonicwall" for product "Sma 500v Firmware"
10.2.1.2-24sv
Search vendor "Sonicwall" for product "Sma 500v Firmware" and version "10.2.1.2-24sv"
-
Affected
in Sonicwall
Search vendor "Sonicwall"
Sma500v
Search vendor "Sonicwall" for product "Sma500v"
--
Safe