CVE-2021-20040: Path Traversal
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2021-20040.
What is the affected software?
The affected software includes Sonicwall SMA 200 firmware version 10.2.0.8-37sv, Sonicwall SMA 210 firmware version 10.2.0.8-37sv, Sonicwall SMA 400 firmware version 10.2.0.8-37sv, Sonicwall SMA 410 firmware version 10.2.0.8-37sv, and Sonicwall SMA 500v firmware version 10.2.0.8-37sv.
What is the severity of CVE-2021-20040?
The severity of CVE-2021-20040 is high, with a CVSS score of 7.5.
How does the vulnerability in the SMA100 upload function work?
The vulnerability allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user, exploiting a relative path traversal vulnerability.
How can I mitigate CVE-2021-20040?
To mitigate this vulnerability, apply the necessary patches or firmware updates provided by Sonicwall. Ensure that your SMA appliances have the latest firmware versions installed.