First published: Thu May 27 2021(Updated: )
A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sonicwall Network Security Manager | <2.2.0 | |
Sonicwall Network Security Manager | =2.2.0 | |
Sonicwall Network Security Manager | =2.2.0-r10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20026.
The severity of CVE-2021-20026 is critical, with a severity value of 8.8.
CVE-2021-20026 allows an authenticated attacker to perform OS command injection using a crafted HTTP request.
CVE-2021-20026 affects NSM On-Prem 2.2.0-R10 and earlier versions.
Yes, updating to a version later than 2.2.0-R10 of NSM On-Prem is recommended to fix CVE-2021-20026.