CVE-2020-5146: OS Command Injection
Published Jan 9, 2021
·Updated
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.
Affected Software
2 affected components
SonicWall Sma 100 Firmware<=10.2.0.2-20sv
SonicWall SMA 100
Event History
Jan 9, 2021
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-5146.
2
What is the severity of CVE-2020-5146?
The severity of CVE-2020-5146 is critical with a severity value of 7.2.
3
What is affected by CVE-2020-5146?
SonicWall SMA100 Appliance version 10.2.0.2-20sv and earlier are affected by CVE-2020-5146.
4
How can an authenticated management-user exploit CVE-2020-5146?
An authenticated management-user can exploit CVE-2020-5146 by performing OS command injection using HTTP POST parameters.
5
How can I fix CVE-2020-5146?
To fix CVE-2020-5146, update your SonicWall SMA100 Appliance to version 10.2.0.2-20sv or later.