CVE-2021-20017: OS Command Injection
Published Mar 13, 2021
·Updated
A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS commands as a 'nobody' user. This vulnerability impacts SMA100 version 10.2.0.5 and earlier.
Affected Software
2 affected components
SonicWall Sma100 Firmware<=10.2.0.5
SonicWall SMA100
Event History
Mar 13, 2021
CVE Published
via MITRE·02:10 AM
Data Sourced
via MITRE·02:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20017?
CVE-2021-20017 is a post-authenticated command injection vulnerability in SonicWall SMA100 that allows an authenticated attacker to execute OS commands as a 'nobody' user.
2
Which version of SonicWall SMA100 is affected by CVE-2021-20017?
SonicWall SMA100 version 10.2.0.5 and earlier are affected by CVE-2021-20017.
3
How can an attacker exploit CVE-2021-20017?
An attacker can exploit CVE-2021-20017 by executing OS commands as a 'nobody' user after authentication.
4
What is the severity of CVE-2021-20017?
CVE-2021-20017 has a severity rating of 8.8, which is considered critical.
5
Is there a fix available for CVE-2021-20017?
Yes, updating to a version later than 10.2.0.5 will fix the vulnerability.