CVE-2021-20034
CRITICALSonicWall SMA 200/210/400/410/500v < 9.0.0.10-28sv - Unauthenticated Arbitrary File Deletion via Path Traversal Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-20034. PoCs published by Jacob Baines.
AI-analyzed exploit summary This exploit leverages a path traversal vulnerability in SonicWall SMA 10.2.1.0-17sv to overwrite the persistent database, allowing an attacker to reset the password on reboot. The exploit uses a crafted curl request to access and modify the database file.
Description
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
Exploits (1)
This exploit leverages a path traversal vulnerability in SonicWall SMA 10.2.1.0-17sv to overwrite the persistent database, allowing an attacker to reset the password on reboot. The exploit uses a crafted curl request to access and modify the database file.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H