SonicWall SMA security advisory-CVE-2021-20028
NAME
SonicWall – Multiple
- Platforms Affected:
Multiple - Risk Level:
high - CVE Type:
SQLi
DESCRIPTION
CVE-2021-20028 is a structured query language injection (SQLi) vulnerability impacting multiple products and versions of SonicWall Secure Mobile Access (SMA). A proof of concept (PoC) was not observed publicly or in the underground. Security researchers claimed the vulnerability was actively exploited in the wild.
CVSS Information:
- CVSS 2.0 SCORE: 7.5
- CVSS 3.0 SCORE: 9.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
MITIGATION
SonicWall addressed the vulnerability in a security advisory with updated versions.
- Reference Link: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0017
- Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.