EXPOSURES › CVE-2021-20035
CVE-2021-20035
HIGH ⌖ ON CISA KEV · EXPLOITEDSonicWall SMA100 appliances had a command injection vulnerability allowing authenticated attackers to execute arbitrary commands remotely as a low-privilege user.
A command injection vulnerability in SonicWall SMA100 appliances allowed authenticated attackers to execute arbitrary commands, potentially leading to code execution. DIB organizations using these appliances face potential data compromise and compliance violations (CMMC DF, MP). Prompt patching and vulnerability scanning are critical.
Shame score — The vulnerability's existence and active exploitation, coupled with SonicWall's history of similar issues, indicates a significant failure in secure development practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.