CVE-2021-20028: SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
UNSUPPORTED WHEN ASSIGNED Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier.
Other sources
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect SonicWall Secure Remote Access (SRA) appliances that are end-of-life and running all 8.x firmware and 9.0.0.9-26sv or earlier from networks (isolate them from production and the internet) if they are still in use.
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20028?
The severity of CVE-2021-20028 is critical with a CVSS score of 9.8.
Which products are affected by CVE-2021-20028?
The affected product is SonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier.
How does CVE-2021-20028 impact the affected products?
CVE-2021-20028 is a SQL Injection vulnerability that can be exploited on end-of-life Secure Remote Access (SRA) products.
How can I fix CVE-2021-20028?
To mitigate the vulnerability, SonicWall recommends upgrading to the latest supported firmware version.
Where can I find more information about CVE-2021-20028?
You can find more information about CVE-2021-20028 on the SonicWall PSIRT website at the following link: [https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0017](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0017)