Executive brief
SonicWall SMA100 contains a SQL injection vulnerability due to improper neutralization of special elements in SQL commands. An unauthenticated remote attacker can exploit this to gain unauthorized read-only access to sensitive resources.
Affected products
- SonicWall SMA 100 firmware 9.0.0.3 and earlier
Timeline
- 2019-12-17: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild