A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
                
            References
                    | Link | Resource | 
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0026 | Vendor Advisory | 
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0026 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
Configuration 3 (hide)
| AND | 
 
 | 
Configuration 4 (hide)
| AND | 
 
 | 
Configuration 5 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2021-12-08 10:15
Updated : 2024-11-21 05:45
NVD link : CVE-2021-20040
Mitre link : CVE-2021-20040
CVE.ORG link : CVE-2021-20040
JSON object : View
Products Affected
                sonicwall
- sma_400
- sma_210_firmware
- sma_210
- sma_410
- sma_500v_firmware
- sma_200
- sma_500v
- sma_410_firmware
- sma_400_firmware
- sma_200_firmware
