Improper Access Control in SonicWall SMA100 Affects Security Features
CVE-2021-20034
9.1CRITICAL
Summary
The SonicWall SMA100 product is subjected to an improper access control vulnerability that enables remote, unauthenticated attackers to bypass path traversal protections. This flaw allows attackers to delete arbitrary files within the system, which could lead to significant issues, such as a complete reboot to factory default settings. Users of the affected version should take immediate action to mitigate potential risks associated with this vulnerability.
Affected Version(s)
SMA100 9.0.0.10-28sv and earlier
SMA100 10.2.0.7-34sv and earlier
SMA100 10.2.1.0-17sv and earlier
References
EPSS Score
29% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved