← KEV catalog
CISA known exploited vulnerability

CVE-2021-20028

SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

SOURCE FACT

SonicWall · Secure Remote Access (SRA)

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

Required action

The impacted product is end-of-life and should be disconnected if still in use.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2021-20028

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?