vuln-advisorystandardsNewsThe Broadside1 min read

SonicWall SMA 100 Flaw Actively Exploited as Severity Jumps to High

SonicWall hasn't disclosed when patches will ship or which version numbers constitute the fix, leaving administrators on three firmware tracks without a remediation timeline.


TL;DR

MS-ISAC warns that CVE-2021-20035, an OS command injection flaw in the SonicWall SMA 100 Series management interface, is now under active exploitation. SonicWall's PSIRT upgraded the CVSS score from medium to high (7.2) on April 15, and CISA added the CVE to its Known Exploited Vulnerabilities catalog the next day with a May 7 remediation deadline under BOD 22-01. Affected models include the SMA 200, 210, 400, 410, and 500v (spanning virtual appliances on ESX, KVM, AWS, and Azure) across three firmware version tracks. SonicWall has not yet published patch version numbers or a release date.

CVE-2021-20035 isn't new, it was disclosed in 2021 as an improper neutralization flaw that lets a remote authenticated attacker inject OS commands as the nobody user on the SMA 100 management interface. But the ground shifted sharply on April 15, when SonicWall's PSIRT confirmed the vulnerability is being actively exploited in the wild and bumped the severity from medium to a 7.2 high. For a unified secure access gateway that sits between employees and the applications they need, that's the kind of escalation that turns a patch- soon item into a patch-now item.

CISA evidently agrees. It added CVE-2021-20035 to the Known Exploited Vulnerabilities catalog on April 16, triggering the Binding Operational Directive 22-01 clock: federal agencies have until May 7 to apply mitigations or discontinue use.

The problem for the engineers and administrators who actually have to do that work is that SonicWall hasn't named the fixed versions. The advisory covers three firmware tracks, 10.2.1.0-17sv and earlier, 10.2.0.7-34sv and earlier, and 9.0.0.10-28sv and earlier, across five hardware models and four virtual deployment targets. Without a published patch version, the best guidance available is the vendor advisory at SNWLID-2021-0022, which for now amounts to "apply appropriate updates" without specifying what those updates are. For organizations running SMA 100 appliances as their remote access backbone, Monday morning starts with a risk call, not a patch window.


Published ·Deep Fathom