Unauthorized Proxy Bypass in SonicWall SMA Appliances
CVE-2021-20042

9.8CRITICAL

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
8 December 2021

Summary

An unauthenticated remote attacker can exploit a vulnerability in SonicWall SMA appliances to use the device as an unintended proxy. This issue enables the attacker to bypass firewall rules and potentially gain access to sensitive internal resources without detection, posing a significant security risk to networks reliant on these appliances.

Affected Version(s)

SonicWall SMA100 9.0.0.11-31sv and earlier

SonicWall SMA100 10.2.0.8-37sv and earlier

SonicWall SMA100 10.2.1.1-19sv and earlier

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.