← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-20034

An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
EPSS Probability:80.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-284 ↗CWE-284: Improper Access Control

Affected Products & Versions

Vendor Product Affected Versions
SonicWall SMA100 9.0.0.10-28sv and earlier (affected), 10.2.0.7-34sv and earlier (affected), 10.2.1.0-17sv and earlier (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
80.701%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySonicWall, Inc. · Vendor · USA
Reserved2020-12-17T00:00:00
Published2021-09-27T17:20:10
Last Updated2024-08-03T17:30:07

LINK COPIED TO CLIPBOARD