CVE-2021-20041
An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100
An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfiles resulting in a loop with unreachable exit condition. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
HIGH · CVSS 7.5
EPSS 0.01317
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0