SQL injection in SonicWall products - CVE-2021-20016

 

SQL injection in SonicWall products - CVE-2021-20016

Published: January 24, 2021 / Updated: February 5, 2021


Vulnerability identifier: #VU49936
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20016
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote non-authenticated attacker can send a specially crafted HTTP request to the SSL-VPN appliance and execute arbitrary SQL commands within the application database.

Successful exploitation of this vulnerability may allow a remote attacker to access usernames, passwords and other session related information.

Note, the vulnerability is being actively exploited in the wild.


Affected software

SMA 100
NetExtender for Windows
NetExtender for Linux

How to mitigate CVE-2021-20016

Install update from vendor's website.

The following products are affected:

Physical appliances – SMA 200, SMA 210, SMA 400 and SMA 410.

Virtual appliance – SMA 500v.


SMA 100 - update to 10.2.0.5-d-29sv

External References

Related Security Bulletins