THREAT OPS › CVEs › CVE-2021-20016
CVE-2021-20016 — SonicWall SSLVPN SMA100 SQL Injection Vulnerability
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
Vulnerability details
- Affected productsSSLVPN SMA100
- KEV remediation due2021-11-17
Related reporting
- [NVD] CVE-2021-20016 (CRITICAL 9.8) — A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.nvd
- CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wildtenable