CVE-2021-20042
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Affected (15)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.0.8-37sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.0.8-37sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 210 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.0.8-37sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 410 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.0.8-37sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 400 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.2.0.8-37sv |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Sma 500v | All versions |
References (2)
Source: PSIRT@sonicwall.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.