CVE-2021-20039
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 78.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 78.75% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- sonicwall/sma 200 firmware · sonicwall/sma 210 firmware · sonicwall/sma 410 firmware · sonicwall/sma 400 firmware · sonicwall/sma 500v firmware
- Source
- PSIRT@sonicwall.com
References
- http://packetstormsecurity.com/files/165563/SonicWall-SMA-100-Series-Authenticated-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0026Vendor Advisory
- http://packetstormsecurity.com/files/165563/SonicWall-SMA-100-Series-Authenticated-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0026Vendor Advisory
- https://attackerkb.com/topics/9szJhq46lw/cve-2021-20039/rapid7-analysis
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.