CVE-2021-20042

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
OR cpe:2.3:o:sonicwall:sma_200_firmware:9.0.0.11-31sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_200_firmware:10.2.0.8-37sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_200_firmware:10.2.1.1-19sv:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
OR cpe:2.3:o:sonicwall:sma_210_firmware:9.0.0.11-31sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:10.2.0.8-37sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_210_firmware:10.2.1.1-19sv:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
OR cpe:2.3:o:sonicwall:sma_410_firmware:9.0.0.11-31sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:10.2.0.8-37sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:10.2.1.1-19sv:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
OR cpe:2.3:o:sonicwall:sma_400_firmware:9.0.0.11-31sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_400_firmware:10.2.0.8-37sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_400_firmware:10.2.1.1-19sv:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
OR cpe:2.3:o:sonicwall:sma_500v_firmware:9.0.0.11-31sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:10.2.0.8-37sv:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:10.2.1.1-19sv:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-12-08 10:15

Updated : 2023-06-26 19:15


NVD link : CVE-2021-20042

Mitre link : CVE-2021-20042

CVE.ORG link : CVE-2021-20042


JSON object : View

Products Affected

sonicwall

  • sma_410_firmware
  • sma_400_firmware
  • sma_500v
  • sma_500v_firmware
  • sma_410
  • sma_200_firmware
  • sma_210
  • sma_200
  • sma_210_firmware
  • sma_400
CWE
NVD-CWE-Other CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')