Executive brief
A SQL injection vulnerability in SonicWall SMA100 series appliances allows a remote, unauthenticated attacker to execute SQL queries. This can be exploited to access sensitive information including usernames, passwords, and session-related data.
Affected products
- SonicWall SMA 100 Firmware 10.x (specifically 10.0.0.0 up to but excluding 10.2.0.5-d-29sv)
- SonicWall SMA 100
- SonicWall SMA 200
- SonicWall SMA 210
- SonicWall SMA 400
- SonicWall SMA 410
- SonicWall SMA 500v
Timeline
- 2021-02-04: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-17: other: CISA Due Date for remediation