Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
| Software | From | Fixed in |
|---|---|---|
| sonicwall / sma_200_firmware | - | 10.2.1.9-57sv.x |
| sonicwall / sma_210_firmware | - | 10.2.1.9-57sv.x |
| sonicwall / sma_400_firmware | - | 10.2.1.9-57sv.x |
| sonicwall / sma_410_firmware | - | 10.2.1.9-57sv.x |
| sonicwall / sma_500v_firmware | - | 10.2.1.9-57sv.x |