EXPOSURES › CVE-2021-20028
CVE-2021-20028
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSonicWall SRA products had a SQL injection vulnerability actively exploited by ransomware actors, potentially allowing unauthorized data access and system compromise.
A SQL injection flaw in SonicWall SRA products allowed attackers to potentially extract data and compromise systems, and was actively exploited in ransomware attacks. DIB organizations using this product face significant compliance risks (NIST 800-171 controls 3.1.1, 3.1.2) and should immediately patch or mitigate the vulnerability. Review network segmentation and access controls.
Shame score — The vulnerability was actively exploited by ransomware groups, indicating a failure to adequately secure a critical product and a significant operational risk for DIB customers.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.