VYPR
High severity8.8NVD Advisory· Published May 27, 2021· Updated Jun 17, 2026

CVE-2021-20026

CVE-2021-20026

Description

A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.

Affected products

5
  • cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:on-premises:*:*:*+ 2 more
    • cpe:2.3:a:sonicwall:network_security_manager:*:*:*:*:on-premises:*:*:*range: <2.2.0
    • cpe:2.3:a:sonicwall:network_security_manager:2.2.0:-:*:*:on-premises:*:*:*
    • cpe:2.3:a:sonicwall:network_security_manager:2.2.0:r10:*:*:on-premises:*:*:*
  • Range: <=2.2.0-R10
  • SonicWall/SonicWall NSM On-Premv5
    Range: NSM On-Prem 2.2.0-R10 and earlier

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.