CVE-2021-20043: Buffer Overflow
Published Dec 8, 2021
·Updated
A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Affected Software
15 affected components
SonicWall Sma 200 Firmware=10.2.0.8-37sv
SonicWall Sma 200 Firmware=10.2.1.1-19sv
SonicWall SMA 200
SonicWall Sma 210 Firmware=10.2.0.8-37sv
SonicWall Sma 210 Firmware=10.2.1.1-19sv
SonicWall Sma 210
SonicWall Sma 410 Firmware=10.2.0.8-37sv
SonicWall Sma 410 Firmware=10.2.1.1-19sv
SonicWall Sma 410
SonicWall Sma 400 Firmware=10.2.0.8-37sv
SonicWall Sma 400 Firmware=10.2.1.1-19sv
SonicWall Sma 400
SonicWall Sma 500v Firmware=10.2.0.8-37sv
SonicWall Sma 500v Firmware=10.2.1.1-19sv
SonicWall Sma 500v
Event History
Dec 8, 2021
CVE Published
via MITRE·09:55 AM
Data Sourced
via MITRE·09:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20043.
2
What is the severity of CVE-2021-20043?
The severity of CVE-2021-20043 is high (8.8).
3
Which SonicWall SMA appliances are affected by CVE-2021-20043?
SMA 200, 210, 400, 410, and 500v appliances are affected by CVE-2021-20043.
4
How does CVE-2021-20043 work?
CVE-2021-20043 is a Heap-based buffer overflow vulnerability in the getBookmarks method of SonicWall SMA100, which allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance.
5
How can I fix CVE-2021-20043?
Apply the latest firmware update provided by SonicWall to mitigate the vulnerability.