Currently being tracked as CVE-2021-20038 and CVE-2021-20039, these severe vulnerabilities could allow for a complete takeover of these appliances, affecting partners using SonicWall products. In their security advisory, SonicWall is urging users to patch immediately.
Important: While there is no evidence that these vulnerabilities are being exploited, an active proof of concept (PoC) exists in the wild.
CVE-2021-20038 is a stack-based buffer overflow in the SMA’s Apache httpd server’s mod_cgi module environment variables allowing remote unauthenticated attackers to obtain code execution on the appliance as a ‘nobody’ user. This means that an attacker could take control of the SMA’s hardware and intercept or redirect network traffic. The vulnerability has been assigned a 9.8 critical base score.
CVE-2021-20039 is a command injection vulnerability where improper neutralization of special elements in SMA’s management interface ‘/cgi-bin/viewcert’ POST http method allows a remote authenticated attacker to inject arbitrary commands as a ‘nobody’ user. Once running as the nobody user, it can be trivial to escalate privileges to the root user. This vulnerability has been assigned an 8.8 high base score.