Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
| Software | From | Fixed in |
|---|---|---|
| sonicwall / sma_200_firmware | - | 9.0.0.11-31sv |
| sonicwall / sma_200_firmware | 10.2.0.0 | 10.2.0.8-37sv |
| sonicwall / sma_200_firmware | 10.2.1.0 | 10.2.1.1-19sv |
| sonicwall / sma_210_firmware | - | 9.0.0.11-31sv |
| sonicwall / sma_210_firmware | 10.2.0.0 | 10.2.0.8-37sv |
| sonicwall / sma_210_firmware | 10.2.1.0 | 10.2.1.1-19sv |
| sonicwall / sma_400_firmware | - | 9.0.0.11-31sv |
| sonicwall / sma_400_firmware | 10.2.0.0 | 10.2.0.8-37sv |
| sonicwall / sma_400_firmware | 10.2.1.0 | 10.2.1.1-19sv |
| sonicwall / sma_410_firmware | - | 9.0.0.11-31sv |
| sonicwall / sma_410_firmware | 10.2.0.0 | 10.2.0.8-37sv |
| sonicwall / sma_410_firmware | 10.2.1.0 | 10.2.1.1-19sv |
| sonicwall / sma_500v | - | 9.0.0.11-31sv |
| sonicwall / sma_500v | 10.2.0.0 | 10.2.0.8-37sv |
| sonicwall / sma_500v | 10.2.1.0 | 10.2.1.1-19sv |