CVE-2021-20035: SonicWall SMA100 Appliances OS Command Injection Vulnerability
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
Other sources
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.
— CISA
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-20035.
What is the severity of CVE-2021-20035?
The severity of CVE-2021-20035 is medium with a score of 6.5.
What is the affected software for CVE-2021-20035?
The affected software for CVE-2021-20035 includes Sonicwall SMA 200 Firmware, Sonicwall SMA 210 Firmware, Sonicwall SMA 400 Firmware, Sonicwall SMA 410 Firmware, and Sonicwall SMA 500v.
How does CVE-2021-20035 impact the system?
CVE-2021-20035 allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, potentially leading to a denial of service (DoS) attack.
Where can I find more information about CVE-2021-20035?
You can find more information about CVE-2021-20035 at the following link: [Sonicwall Advisory](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022)