CVE-2021-20028SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

PUBLISHEDvulnerability record
2022-03-28 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2021-20028
Project:
SonicWall
Product:
Secure Remote Access (SRA)
Date Added:
2022-03-28
Due Date:
2022-04-18
Last Updated:
June 21, 2025

Vulnerability Name

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

Description

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

The impacted product is end-of-life and should be disconnected if still in use.

Additional Notes

Related Weaknesses