CVE Vulnerabilities

CVE-2021-20042

Published: Dec 08, 2021 | Modified: Jun 26, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

Affected Software

Name Vendor Start Version End Version
Sma_200_firmware Sonicwall 9.0.0.11-31sv (including) 9.0.0.11-31sv (including)
Sma_200_firmware Sonicwall 10.2.0.8-37sv (including) 10.2.0.8-37sv (including)
Sma_200_firmware Sonicwall 10.2.1.1-19sv (including) 10.2.1.1-19sv (including)

References