Vulnerability Database

300,926

Total vulnerabilities in the database

CVE-2021-20042

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

  • Published: Dec 8, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2021-20042
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
sonicwall / sma_200_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_200_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_200_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_210_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_210_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_210_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_410_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_410_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_410_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_400_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_400_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_400_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x
sonicwall / sma_500v_firmware 9.0.0.11-31sv 9.0.0.11-31sv.x
sonicwall / sma_500v_firmware 10.2.0.8-37sv 10.2.0.8-37sv.x
sonicwall / sma_500v_firmware 10.2.1.1-19sv 10.2.1.1-19sv.x