CVE-2021-20038
CRITICALA Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.
Affected Products
sma 200 firmwaresonicwallsma 210 firmwaresonicwallsma 400 firmwaresonicwallsma 410 firmwaresonicwallsma 500v firmwaresonicwallResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd serve…
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd serve…
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd serve…
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd serve…
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd serve…
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd serve…
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd serve…
Frequently Asked Questions
Is CVE-2021-20038 in your stack?
O3 detects CVE-2021-20038 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.