Home / Vulnerabilities / CVE-2021-20035
MEDIUM SEVERITY
CVE-2021-20035 SonicWall · SMA100 Appliances

SonicWall SMA100 Appliances OS Command Injection Vulnerability

Technical Severity

CVSS v3.1 Metrics

MEDIUM
6.5 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitation Likelihood

EPSS Prediction

3.97 %
Predictive Probability
Percentile Rank
88.1 th

Documented as more likely to be exploited than 88.1% of known CVEs.

Detection Date

Apr 16, 2025

Remediation Due

May 07, 2025

CISA Catalog Active

Threat Analysis

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

Remediation Directive

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

External Intelligence