Vulnerabilities > Sonicwall > SMA 210 Firmware > 9.0.0.11.31sv
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-08 | CVE-2021-20039 | OS Command Injection vulnerability in Sonicwall products Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. | 8.8 |
2021-12-08 | CVE-2021-20041 | Infinite Loop vulnerability in Sonicwall products An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. | 7.5 |
2021-12-08 | CVE-2021-20042 | Unspecified vulnerability in Sonicwall products An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. | 9.8 |