Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 05 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sonicwall
Published:
Updated: 2025-09-05T17:09:47.136Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20039
Updated: 2024-08-03T17:30:07.406Z
Status : Modified
Published: 2021-12-08T10:15:07.903
Modified: 2025-09-05T18:15:35.313
Link: CVE-2021-20039
No data.
OpenCVE Enrichment
No data.
Weaknesses