Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
2021-08-04T19:15:08.247
2025-03-14T16:47:20.140
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sonicwall | sma_210_firmware | < 9.0.0.10-28sv | Yes |
Hardware | sonicwall | sma_210 | - | No |
Operating System | sonicwall | sma_410_firmware | < 9.0.0.10-28sv | Yes |
Hardware | sonicwall | sma_410 | - | No |
Operating System | sonicwall | sma_500v_firmware | < 9.0.0.10-28sv | Yes |
Hardware | sonicwall | sma_500v | - | No |
Operating System | sonicwall | sra_4600_firmware | < 9.0.0.10-28sv | Yes |
Hardware | sonicwall | sra_4600 | - | No |
Operating System | sonicwall | sra_1600_firmware | < 9.0.0.10-28sv | Yes |
Hardware | sonicwall | sra_1600 | - | No |
Operating System | sonicwall | sra_va_firmware | < 9.0.0.10-28sv | Yes |
Hardware | sonicwall | sra_va | - | No |