Junglewise Threat Intelligence

CVE-2021-20038: SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

CVE-2021-20038 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-28

Vendors: SonicWall.

Executive brief

A stack-based buffer overflow vulnerability exists in the SonicWall SMA 100 series Apache httpd server's mod_cgi module. Remote unauthenticated attackers can exploit this via environment variables to execute arbitrary code as the 'nobody' user.

Affected products

  • SonicWall SMA 200 firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions
  • SonicWall SMA 210 firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions
  • SonicWall SMA 400 firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions
  • SonicWall SMA 410 firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions
  • SonicWall SMA 500v firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions

Timeline

  • 2022-01-11: patched: Rapid7 reported fixes for multiple vulnerabilities including CVE-2021-20038.
  • 2022-01-28: disclosed: NVD publication date.
  • 2022-01-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-01-28: exploited: Reported as exploited in the wild.