Critical severity9.1NVD Advisory· Published Sep 27, 2021· Updated Jun 17, 2026
CVE-2021-20034
CVE-2021-20034
Description
An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*Range: <=9.0.0.10-28sv
- cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*Range: <=9.0.0.10-28sv
- cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*Range: <=9.0.0.10-28sv
- cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*Range: <=9.0.0.10-28sv
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/164564/SonicWall-SMA-10.2.1.0-17sv-Password-Reset.htmlnvdExploitThird Party AdvisoryVDB Entry
- psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0021nvdVendor Advisory
News mentions
0No linked articles in our index yet.