CVE-2021-20035

CVE-2021-20035

Vendor Sonicwall
Product SMA100
Weakness CWE-78
KEV Status Known Exploited
Published September 27, 2021
Last update October 21, 2025

CVSS base score

What the vulnerability does

01Description

Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.

CISA mandated remediation

02CISA Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Key dates

03Disclosure timeline

September 27, 2021 CVE published
October 21, 2025 Record updated