SQL Injection Vulnerability SonicWall SMA Appliances
ID: 69b29f68-6d3f-560e-9661-96d4c0b763e4
STIX ID: report--69b29f68-6d3f-560e-9661-96d4c0b763e4
Feed Name: Arctic Wolf Blog
Arctic Wolf summarizes SonicWall's disclosure of a zero-day SQL injection (CVE-2021-20016) affecting SMA 100 Series appliances, which enables unauthenticated attackers to extract user credentials and potentially access appliance web interfaces to pivot into networks. SonicWall released firmware 10.2.0.5-29sv to patch the issue; Arctic Wolf recommends updating firmware, resetting passwords, and enabling multifactor authentication, noting researchers have observed exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
