VYPR
Unrated severityNVD Advisory· Published Dec 23, 2021· Updated Aug 3, 2024

CVE-2021-20049

CVE-2021-20049

Description

A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.

Affected products

2
  • SonicWall/SMA100llm-fuzzy
    Range: <=10.2.1.2-24sv
  • SonicWall/SonicWall SMA100v5
    Range: 10.2.0.8-37sv and earlier

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.