CyberSec.Space Logo
CVEブラウザに戻る

CVE-2021-20028

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score50.1100%
EPSS Percentile97.70th
Published2021年8月4日
Last Modified2025年10月31日

Vulnerability Description

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

Affected Platforms (CPE)

💻
Sonicwall

Sma 210 Firmware

>= 8.0.0.0 and < 9.0.0.10-28sv
💻
Sonicwall

Sma 410 Firmware

>= 8.0.0.0 and < 9.0.0.10-28sv
💻
Sonicwall

Sma 500v Firmware

>= 8.0.0.0 and < 9.0.0.10-28sv
💻
Sonicwall

Sra 4600 Firmware

>= 8.0.0.0 and < 9.0.0.10-28sv
💻
Sonicwall

Sra 1600 Firmware

>= 8.0.0.0 and < 9.0.0.10-28sv
💻
Sonicwall

Sra Va Firmware

>= 8.0.0.0 and < 9.0.0.10-28sv

References & Advisories

関連する脆弱性情報