Executive brief
SonicWall Secure Remote Access (SRA) and SMA products contain an improper neutralization of SQL commands, leading to a critical SQL injection vulnerability. The flaw impacts end-of-life SRA appliances running 8.x or early 9.x firmware, potentially allowing unauthenticated remote attackers to execute arbitrary SQL queries.
Affected products
- SonicWall Secure Remote Access (SRA) firmware 8.x, 9.0.0.9-26sv or earlier
- SonicWall SMA 210 firmware 8.0.0.0 to 9.0.0.10-28sv
- SonicWall SMA 410 firmware 8.0.0.0 to 9.0.0.10-28sv
- SonicWall SMA 500v firmware 8.0.0.0 to 9.0.0.10-28sv
Timeline
- 2021-02-01: disclosed: SonicWall PSIRT Advisory SNWLID-2021-0017 published
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-28: advisory: NVD publication date