Skip to content
COOEY

EXPOSURES › CVE-2021-20016

CVE-2021-20016

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20016 ↗
◐ ZERO-DAY ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

SonicWall's SMA100 VPN devices had a SQL injection flaw allowing unauthorized access to credentials, and it was actively exploited in the wild.

An unauthenticated attacker could exploit a SQL injection vulnerability in SonicWall's SMA100 VPN devices to access credentials. This poses a significant risk to DIB organizations using these devices, potentially leading to data breaches and compliance failures (CMMC DFAT/NFAT). Immediate patching and security assessment are crucial.

Shame score — The vulnerability allowed unauthenticated access and was actively exploited, indicating a failure in secure coding practices and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Unauthenticated SQL injection allowing credential theft is a severe security failure, though the provided source is purely factual without commentary on SonicWall's response or industry reaction.
cooey ↗ severe-fallout +0.00
neutral
"SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.