EXPOSURES › CVE-2021-20016
CVE-2021-20016
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSonicWall's SMA100 VPN devices had a SQL injection flaw allowing unauthorized access to credentials, and it was actively exploited in the wild.
An unauthenticated attacker could exploit a SQL injection vulnerability in SonicWall's SMA100 VPN devices to access credentials. This poses a significant risk to DIB organizations using these devices, potentially leading to data breaches and compliance failures (CMMC DFAT/NFAT). Immediate patching and security assessment are crucial.
Shame score — The vulnerability allowed unauthenticated access and was actively exploited, indicating a failure in secure coding practices and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
"SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker."