CVE-2021-20016: SonicWall SSLVPN SMA100 SQL Injection Vulnerability
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
Other sources
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20016.
What is the title of the vulnerability?
The title of the vulnerability is SonicWall SSLVPN SMA100 SQL Injection Vulnerability.
What is the severity of CVE-2021-20016?
The severity of CVE-2021-20016 is critical with a CVSS score of 9.8.
Which version of SonicWall SSLVPN SMA100 is affected?
The SQL Injection vulnerability impacts SMA100 build version 10.x.
How can an attacker exploit CVE-2021-20016?
A remote unauthenticated attacker can exploit this vulnerability by performing SQL queries to access username, password, and other session related information.
Is SonicWall SSLVPN SMA200 affected by CVE-2021-20016?
No, SonicWall SSLVPN SMA200 is not affected by this vulnerability.
Where can I find more information about CVE-2021-20016?
You can find more information about CVE-2021-20016 on the SonicWall PSIRT website at the following link: [https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001)