CVE-2021-20016
CRITICALA SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related…
Description
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
Affected Products
sma 100 firmwaresonicwallsma 200 firmwaresonicwallsma 210 firmwaresonicwallsma 400 firmwaresonicwallsma 410 firmwaresonicwallsma 500vsonicwallResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Frequently Asked Questions
Is CVE-2021-20016 in your stack?
O3 detects CVE-2021-20016 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.