CVE-2021-20028: SonicWall Secure Remote Access (SRA)
EPSS30.0%No. 1006 of 1739 in KEV
CVE year2021~1 yrs before listing
Same vendor in KEV19
Same product1
| Field | Value |
|---|---|
| Vendor | SonicWall |
| Product | Secure Remote Access (SRA) |
| Name | SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability |
| Added to KEV | 2022-03-28 |
| US federal due date | 2022-04-18 |
| Ransomware use | Known |
| CWE | CWE-89 |
CISA description
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A SonicWall Secure Remote Access (SRA) vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28.