QID 375597

QID 375597: SonicWall Network Security Manager Authenticated Command Injection Vulnerability (SNWLID-2021-0014)

SonicWall Network Security Manager (NSM) allows to centrally manage firewall operations, threats and risks across firewall ecosystems.

A vulnerability in SonicWall NSM On-Prem allows an authenticated attacker to perform OS command injection using a crafted HTTP request.

Affected Products:
SonicWall Network Security Manager On-Prem 2.2.0-R10 and earlier versions

Successful exploitation allows an authenticated attacker to perform OS command injection.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Please refer to SNWLID-2021-0014 for more information about patching these vulnerabilities.
    Vendor References

    CVEs related to QID 375597

    Software Advisories
    Advisory ID Software Component Link
    SNWLID-2021-0014 URL Logo psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0014