CVE-2021-20035: SonicWall SMA100 Appliances
EPSS4.1%No. 1449 of 1739 in KEV
CVE year2021~4 yrs before listing
Same vendor in KEV19
Same product2
| Field | Value |
|---|---|
| Vendor | SonicWall |
| Product | SMA100 Appliances |
| Name | SonicWall SMA100 Appliances OS Command Injection Vulnerability |
| Added to KEV | 2025-04-16 |
| US federal due date | 2025-05-07 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2023-44221 | SonicWall SMA100 Appliances | 2025-05-01 | 76.2% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A SonicWall SMA100 Appliances vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-04-16.