CVE-2021-20034: Path Traversal
Published Sep 27, 2021
·Updated
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
Affected Software
19 affected components
SonicWall Sma 200 Firmware<=9.0.0.10-28sv
SonicWall Sma 200 Firmware>=10.2.0.0<=10.2.0.7-34sv
SonicWall Sma 200 Firmware>=10.2.1.0<=10.2.1.0-17sv
SonicWall SMA 200
SonicWall Sma 210 Firmware<=9.0.0.10-28sv
SonicWall Sma 210 Firmware>=10.2.0.0<=10.2.0.7-34sv
SonicWall Sma 210 Firmware>=10.2.1.0<=10.2.1.0-17sv
SonicWall Sma 210
SonicWall Sma 400 Firmware<=9.0.0.10-28sv
SonicWall Sma 400 Firmware>=10.2.0.0<=10.2.0.7-34sv
SonicWall Sma 400 Firmware>=10.2.1.0<=10.2.1.0-17sv
SonicWall Sma 400
SonicWall Sma 410 Firmware<=9.0.0.10-28sv
SonicWall Sma 410 Firmware>=10.2.0.0<=10.2.0.7-34sv
SonicWall Sma 410 Firmware>=10.2.1.0<=10.2.1.0-17sv
SonicWall Sma 410
SonicWall Sma 500v<=9.0.0.10-28sv
SonicWall Sma 500v>=10.2.0.0<=10.2.0.7-34sv
SonicWall Sma 500v>=10.2.1.0<=10.2.1.0-17sv
Event History
Sep 27, 2021
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20034?
The severity of CVE-2021-20034 is critical with a CVSS score of 9.1.
2
How does CVE-2021-20034 affect Sonicwall SMA?
CVE-2021-20034 affects Sonicwall SMA 200, 210, 400, 410, and 500v firmware versions.
3
How can an attacker exploit CVE-2021-20034?
An attacker can exploit CVE-2021-20034 by bypassing the path traversal checks and deleting an arbitrary file on an affected device.
4
What is the impact of CVE-2021-20034?
The impact of CVE-2021-20034 is the potential for an attacker to reboot the affected device to factory default settings.
5
Is there a fix available for CVE-2021-20034?
Yes, Sonicwall has released firmware updates to address the vulnerability in SMA 200, 210, 400, 410, and 500v.