Vulnerability record · CVE-2021-20016 · published 4 February 2021
CVE-2021-20016: SonicWall SMA100 SSLVPN SQL injection allows unauthenticated access
Sonicwall · Sma 100 Firmware
SonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to read usernames, passwords and session data from the appliance database. Because the device is an internet-facing remote-access gateway, compromise exposes both the appliance and the sessions it brokers.
Description
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote SQL injection on an internet-facing VPN gateway with a 9.8 CVSS score, KEV listing and ransomware use makes this an urgent patch-first issue.
What it is
SonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to read usernames, passwords and session data from the appliance database. Because the device is an internet-facing remote-access gateway, compromise exposes both the appliance and the sessions it brokers.
Impact
An unauthenticated attacker gains read access to stored credentials and session information, which can be reused to log in as legitimate users or administrators and pivot into the protected network.
Attack surface
Reachable over the network through the SSLVPN web interface; the CVSS vector shows no privileges and no user interaction required, so any host that can reach the appliance can attempt the injection.
Exploitation
Listed in CISA KEV with a 2021-11-17 remediation due date and flagged for known ransomware campaign use; EPSS 30-day probability is about 0.40 (98.6th percentile), indicating active exploitation is likely.
What to do
- Apply the vendor update for SMA100 10.x per SonicWall PSIRT advisory SNWLID-2021-0001; patch is the only complete fix.
- If patching cannot be done immediately, apply the mitigations in the SonicWall advisory and restrict SSLVPN exposure to trusted networks.
- Rotate credentials and invalidate sessions for all accounts that authenticate through the SMA appliance, since stored usernames, passwords and session data may have been read.
- Enable and forward SMA logs to a central SIEM so injection attempts and anomalous logins are retained.
- Review the appliance for unauthorized accounts, configuration changes or persistence after any suspected exposure.
Detection
- Search SMA/SSLVPN web logs for SQL metacharacters (quotes, UNION, OR 1=1, comment sequences) in request parameters and URIs.
- Alert on authentication events from unexpected source IPs or at unusual times for accounts that use the SMA gateway.
- Monitor for repeated failed or malformed requests to SSLVPN endpoints from a single source, which may indicate automated injection attempts.
- Correlate SMA log entries with downstream authentication and lateral-movement activity to catch credential reuse after a successful injection.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20016 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall SSLVPN SMA100 SQL Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001 | MitigationVendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001 | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20016 | US Government Resource |
Track CVE-2021-20016 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20016), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.