CVE-2021-20039: OS Command Injection
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-20039.
What is the severity level of CVE-2021-20039?
The severity level of CVE-2021-20039 is critical with a score of 8.8.
Which Sonicwall devices are affected by CVE-2021-20039?
Sonicwall SMA 200, 210, 400, 410, and 500v appliances are affected by CVE-2021-20039.
How does CVE-2021-20039 allow an attacker to exploit the vulnerability?
CVE-2021-20039 allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user through the SMA100 management interface '/cgi-bin/viewcert' POST http method.
Are Sonicwall SMA 200, 210, 400, 410, and 500v appliances vulnerable to CVE-2021-20039?
Yes, Sonicwall SMA 200, 210, 400, 410, and 500v appliances are vulnerable to CVE-2021-20039.