CISA Known Exploited Vulnerability

CVE-2021-20016 Ransomware

SonicWall · SSLVPN SMA100

SonicWall SSLVPN SMA100 SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Known

CISA description

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

Required action

Apply updates per vendor instructions.