Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.
| Software | From | Fixed in |
|---|---|---|
| sonicwall / sma_210_firmware | - | 10.2.1.4-31sv.x |
| sonicwall / sma_410_firmware | - | 10.2.1.4-31sv.x |
| sonicwall / sma_500v_firmware | - | 10.2.1.4-31sv.x |
| sonicwall / sma_210_firmware | - | 10.2.0.9-41sv.x |
| sonicwall / sma_410_firmware | - | 10.2.0.9-41sv.x |
| sonicwall / sma_500v_firmware | - | 10.2.0.9-41sv.x |