CVE-2021-20049: High severity sonicwall sma 100 vulnerability
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20049?
The severity of CVE-2021-20049 is high, with a severity value of 7.5.
Which SonicWall SMA100 firmware versions are affected by CVE-2021-20049?
SonicWall SMA100 firmware versions 10.2.1.2-24sv, 10.2.0.8-37sv, and earlier 10.x versions are affected by CVE-2021-20049.
What is the vulnerability in SonicWall SMA100 password change API?
The vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses.
Is the SonicWall SMA200 firmware affected by CVE-2021-20049?
No, the SonicWall SMA200 firmware is not affected by CVE-2021-20049.
How can I fix the CVE-2021-20049 vulnerability in SonicWall SMA100?
To fix the CVE-2021-20049 vulnerability in SonicWall SMA100, update to a version that is not affected, such as 10.2.1.2-25sv.