CVE-2021-20034
CRITICALSonicwall Sma 200 Firmware < 9.0.0.10-28sv - Improper Access Control
Title source: ruleDescription
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
Exploits (1)
exploitdb
WORKING POC
by Jacob Baines · textwebappshardware
https://www.exploit-db.com/exploits/50430
Scores
CVSS v3
9.1
EPSS
0.0578
EPSS Percentile
90.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-284
CWE-22
Status
published
Products (5)
sonicwall/sma_200_firmware
< 9.0.0.10-28sv
sonicwall/sma_210_firmware
< 9.0.0.10-28sv
sonicwall/sma_400_firmware
< 9.0.0.10-28sv
sonicwall/sma_410_firmware
< 9.0.0.10-28sv
sonicwall/sma_500v
< 9.0.0.10-28sv
Published
Sep 27, 2021
Tracked Since
Feb 18, 2026