Skip to content
COOEY

EXPOSURES › CVE-2021-20038

CVE-2021-20038

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20038 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

SonicWall SMA 100 appliances had a critical, actively exploited buffer overflow vulnerability allowing code execution without authentication.

An unauthenticated stack-based buffer overflow in SonicWall SMA 100 appliances allowed for remote code execution, which has been actively exploited. DIB organizations using these devices face significant risk of compromise and potential non-compliance with CMMC/NIST 800-171. Immediate patching and network segmentation are required.

Shame score — The vulnerability's ease of exploitation and active exploitation demonstrate a significant failure in SonicWall's security engineering and patch management, impacting customer trust.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.