A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.html | Exploit Third Party Advisory VDB Entry |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0019 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
No history.
Information
Published : 2021-10-12 23:15
Updated : 2021-10-19 23:10
NVD link : CVE-2021-20031
Mitre link : CVE-2021-20031
CVE.ORG link : CVE-2021-20031
JSON object : View
Products Affected
sonicwall
- tz270w
- tz300w
- supermassive_9200
- tz350
- soho_250w
- nsa_9650
- nsa_9250
- nsa_2700
- nsa_6650
- supermassive_e10800
- nsv_800
- tz400w
- nsa_4650
- tz270
- nsv_50
- supermassive_e10200
- nsa_4700
- tz600
- nsa_3700
- nsv_25
- nsa_2650
- tz500
- nsv_270
- nsv_870
- tz370
- tz570p
- nsv_10
- supermassive_e10400
- tz350w
- tz470
- nsv_470
- nsa_9450
- nsa_5650
- tz670
- nsv_100
- nsv_1600
- tz600p
- supermassive_9400
- nsa_3650
- tz470w
- sonicos
- supermassive_9800
- tz570w
- tz300p
- tz370w
- nsa_6700
- nsv_300
- tz570
- nssp_12800
- nssp_15700
- nssp_13700
- nsv_400
- nssp_12400
- tz400
- tz500w
- tz300
- nsv_200
- soho_250
- supermassive_9600
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')