CISA Flags Actively Exploited Vulnerability in SonicWall SMA Devices
Based on indications of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a security vulnerability affecting SonicWall Secure Mobile Access (SMA) 100 Series gateways to its list of known exploited vulnerabilities (KEVs).
Tracked as CVE-2021-20035 (CVSS score: 7.2), the high-severity vulnerability pertains to an instance of operating system command injection that may lead to code execution.
According to a September 2021 advisory from SonicWall, "a remote authenticated attacker can inject arbitrary commands as a 'nobody' user if special elements in the SMA100 management interface are not properly neutralized. This could potentially result in code execution."
The defect affects devices running the versions of read more about CIS...

