First published: Sat Jan 09 2021(Updated: )
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sonicwall Sma 100 Firmware | <=10.2.0.2-20sv | |
Sonicwall Sma 100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-5146.
The severity of CVE-2020-5146 is critical with a severity value of 7.2.
SonicWall SMA100 Appliance version 10.2.0.2-20sv and earlier are affected by CVE-2020-5146.
An authenticated management-user can exploit CVE-2020-5146 by performing OS command injection using HTTP POST parameters.
To fix CVE-2020-5146, update your SonicWall SMA100 Appliance to version 10.2.0.2-20sv or later.