← Vulnerability feed

Vulnerability record · CVE-2021-20016 · published 4 February 2021

CVE-2021-20016: SonicWall SMA100 SSLVPN SQL injection allows unauthenticated access

Sonicwall · Sma 100 Firmware

SonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to read usernames, passwords and session data from the appliance database. Because the device is an internet-facing remote-access gateway, compromise exposes both the appliance and the sessions it brokers.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 40% · top 1.4% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
40%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
6Affected product versions listed by NVD
3References
12 Aug 2026Last modified by NVD

Description

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote SQL injection on an internet-facing VPN gateway with a 9.8 CVSS score, KEV listing and ransomware use makes this an urgent patch-first issue.

What it is

SonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to read usernames, passwords and session data from the appliance database. Because the device is an internet-facing remote-access gateway, compromise exposes both the appliance and the sessions it brokers.

Impact

An unauthenticated attacker gains read access to stored credentials and session information, which can be reused to log in as legitimate users or administrators and pivot into the protected network.

Attack surface

Reachable over the network through the SSLVPN web interface; the CVSS vector shows no privileges and no user interaction required, so any host that can reach the appliance can attempt the injection.

Exploitation

Listed in CISA KEV with a 2021-11-17 remediation due date and flagged for known ransomware campaign use; EPSS 30-day probability is about 0.40 (98.6th percentile), indicating active exploitation is likely.

What to do

  • Apply the vendor update for SMA100 10.x per SonicWall PSIRT advisory SNWLID-2021-0001; patch is the only complete fix.
  • If patching cannot be done immediately, apply the mitigations in the SonicWall advisory and restrict SSLVPN exposure to trusted networks.
  • Rotate credentials and invalidate sessions for all accounts that authenticate through the SMA appliance, since stored usernames, passwords and session data may have been read.
  • Enable and forward SMA logs to a central SIEM so injection attempts and anomalous logins are retained.
  • Review the appliance for unauthorized accounts, configuration changes or persistence after any suspected exposure.

Detection

  • Search SMA/SSLVPN web logs for SQL metacharacters (quotes, UNION, OR 1=1, comment sequences) in request parameters and URIs.
  • Alert on authentication events from unexpected source IPs or at unusual times for accounts that use the SMA gateway.
  • Monitor for repeated failed or malformed requests to SSLVPN endpoints from a single source, which may indicate automated injection attempts.
  • Correlate SMA log entries with downstream authentication and lateral-movement activity to catch credential reuse after a successful injection.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-20016 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall SSLVPN SMA100 SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20038SonicWall SMA 100 appliances stack buffer overflow in mod_cgiA stack-based buffer overflow in the Apache httpd mod_cgi module of SonicWall SMA 100 series appliances lets a remote unauthenticated attacker overwr…KEVEPSS 100%analysed9.8CVE-2021-20028SonicWall SRA appliances SQL injection in end-of-life firmwareSonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL in…KEVEPSS 30%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed7.5CVE-2019-7483SonicWall SMA100 unauthenticated directory traversal in handleWAFRedirect CGISonicWall SMA100 firmware contains an unauthenticated directory traversal flaw in the handleWAFRedirect CGI. The description states the flaw lets a u…KEVEPSS 4.0%analysed7.5CVE-2019-7481SonicWall SMA100 SQL injection allows unauthenticated read accessSonicWall SMA100 firmware version 9.0.0.3 and earlier contains a SQL injection flaw (CWE-89) that lets an unauthenticated remote user read resources …KEVEPSS 100%analysed7.2CVE-2023-44221SonicWall SMA100 SSL-VPN management interface OS command injectionThe SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds adminis…KEVEPSS 76%analysed6.5CVE-2021-20035SonicWall SMA100 management interface OS command injectionThe SMA100 management interface fails to neutralize special elements, letting a remote authenticated attacker inject arbitrary commands that run as t…KEVEPSS 4.2%analysed9.8CVE-2022-22273Sonicwall sma 200 firmware os command injection vulnerabilityImproper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2021-20016), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.