Vulnerability Database

318,275

Total vulnerabilities in the database

CVE-2021-20042

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

  • Published: Dec 8, 2021
  • Updated: Nov 16, 2025
  • CVE: CVE-2021-20042
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
Software From Fixed in
sonicwall / sma_200_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_200_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_200_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_210_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_210_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_210_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_410_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_410_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_410_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_400_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_400_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_400_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_500v_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_500v_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_500v_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x