CVE-2021-20038

SonicWall SMA 100 Appliances: Stack-Based Buffer Overflow

As of , CVE-2021-20038 in SonicWall SMA 100 Appliances is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 28 January 2022
US federal deadline
11 February 202214 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Known
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.

CISA's description

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

The CVE record's description, from sonicwall

CVE published
8 December 2021
Assigned by
sonicwall
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-121
Stack-based Buffer Overflow
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Read further