CVE-2021-20045
CRITICALSonicwall Sma 200 Firmware - Buffer Overflow
Title source: ruleDescription
A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Scores
CVSS v3
9.8
EPSS
0.0448
EPSS Percentile
88.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-120
Status
published
Affected Products (10)
sonicwall/sma_200_firmware
sonicwall/sma_200_firmware
sonicwall/sma_210_firmware
sonicwall/sma_210_firmware
sonicwall/sma_410_firmware
sonicwall/sma_410_firmware
sonicwall/sma_400_firmware
sonicwall/sma_400_firmware
sonicwall/sma_500v_firmware
sonicwall/sma_500v_firmware
Timeline
Published
Dec 08, 2021
Tracked Since
Feb 18, 2026