CVE-2021-20016: SonicWall SSLVPN SMA100 SQL Injection Vulnerability.
SonicWall SSLVPN SMA100 SQL Injection Vulnerability. SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
- CISA KEV-listed (remediation due 2021-11-17)
- used in ransomware campaigns
- EPSS 79.8% (99.1% percentile)