{"id":"CVE-2021-20016","title":"A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information","summary":"A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-89","CWE-89"],"vendor":"sonicwall","product":"sma_500v","affected":["sma_100_firmware >= 10.0.0.0, < 10.2.0.5-d-29sv","sma_200_firmware","sma_210_firmware","sma_400_firmware","sma_410_firmware","sma_500v"],"patched":["sma_100_firmware 10.2.0.5-d-29sv"],"published":"2021-02-04","updated":"2026-08-12","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-20016","references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001","label":"PSIRT@sonicwall.com"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20016","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.40038,"epssPercentile":0.98607,"kev":true,"kevDateAdded":"2021-11-03","kevDueDate":"2021-11-17","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-12T19:54:25.512Z","slug":"CVE-2021-20016","body":"## Overview\n\nA SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.\n\n## Affected\n\n- `sma_100_firmware >= 10.0.0.0, < 10.2.0.5-d-29sv`\n- `sma_200_firmware`\n- `sma_210_firmware`\n- `sma_400_firmware`\n- `sma_410_firmware`\n- `sma_500v`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sma_100_firmware 10.2.0.5-d-29sv`","depth":"hadal","depthScore":92,"depthScoreParts":{"impact":53.9,"likelihood":8,"exploitation":25,"ransomware":5},"changes":[]}