VYPR
Unrated severityCISA KEVNVD Advisory· Published Dec 8, 2021· Updated Oct 21, 2025

CVE-2021-20038

CVE-2021-20038

Description

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

Affected products

1
  • SonicWall/SonicWall SMA100v5
    Range: 10.2.0.8-37sv and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.