← Vulnerability feed

Vulnerability record · CVE-2021-20043 · published 8 December 2021

CVE-2021-20043: Sonicwall sma 200 firmware heap-based buffer overflow vulnerability

Sonicwall · Sma 200 Firmware

A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

8.8 CVSS 3.1 High EPSS 23% · top 2.3% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.5
23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code as the nobody user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20043 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20038SonicWall SMA 100 appliances stack buffer overflow in mod_cgiA stack-based buffer overflow in the Apache httpd mod_cgi module of SonicWall SMA 100 series appliances lets a remote unauthenticated attacker overwr…KEVEPSS 100%analysed9.8CVE-2021-20028SonicWall SRA appliances SQL injection in end-of-life firmwareSonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL in…KEVEPSS 30%analysed9.8CVE-2021-20016SonicWall SMA100 SSLVPN SQL injection allows unauthenticated accessSonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to …KEVEPSS 40%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed7.2CVE-2023-44221SonicWall SMA100 SSL-VPN management interface OS command injectionThe SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds adminis…KEVEPSS 76%analysed6.5CVE-2021-20035SonicWall SMA100 management interface OS command injectionThe SMA100 management interface fails to neutralize special elements, letting a remote authenticated attacker inject arbitrary commands that run as t…KEVEPSS 4.2%analysed9.8CVE-2022-22273Sonicwall sma 200 firmware os command injection vulnerabilityImproper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…EPSS 1.9%9.8CVE-2021-20042Sonicwall sma 200 firmware vulnerabilityAn unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2021-20043), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.