← Back

CVE-2021-20042

nvd nist
Published: Dec 8, 2021Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

Affected (15)

5 products
Sma 200 Firmware
Sma 210 Firmware
Sma 410 Firmware
Sma 400 Firmware
Sma 500v Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sonicwall
Version 10.2.0.8-37sv
Version 10.2.1.1-19sv
Version 9.0.0.11-31sv
Running on/withPlatform Versions
Sonicwall
Sma 200
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sonicwall
Version 10.2.0.8-37sv
Version 10.2.1.1-19sv
Version 9.0.0.11-31sv
Running on/withPlatform Versions
Sonicwall
Sma 210
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sonicwall
Version 10.2.0.8-37sv
Version 10.2.1.1-19sv
Version 9.0.0.11-31sv
Running on/withPlatform Versions
Sonicwall
Sma 410
All versions
Configuration D
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sonicwall
Version 10.2.0.8-37sv
Version 10.2.1.1-19sv
Version 9.0.0.11-31sv
Running on/withPlatform Versions
Sonicwall
Sma 400
All versions
Configuration E
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Sonicwall
Version 10.2.0.8-37sv
Version 10.2.1.1-19sv
Version 9.0.0.11-31sv
Running on/withPlatform Versions
Sonicwall
Sma 500v
All versions

References (2)

Source: PSIRT@sonicwall.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.