CISA Known Exploited Vulnerability

CVE-2021-20028 Ransomware

SonicWall · Secure Remote Access (SRA)

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

Date added
BOD 22-01 due date
CWE CWE-89
Ransomware Known

CISA description

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

Required action

The impacted product is end-of-life and should be disconnected if still in use.