Improper Access Control in SonicWall SMA100 Affects Security Features
CVE-2021-20034
9.1CRITICAL
What is CVE-2021-20034?
The SonicWall SMA100 product is subjected to an improper access control vulnerability that enables remote, unauthenticated attackers to bypass path traversal protections. This flaw allows attackers to delete arbitrary files within the system, which could lead to significant issues, such as a complete reboot to factory default settings. Users of the affected version should take immediate action to mitigate potential risks associated with this vulnerability.
Affected Version(s)
SMA100 9.0.0.10-28sv and earlier
SMA100 10.2.0.7-34sv and earlier
SMA100 10.2.1.0-17sv and earlier