LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-20016: SonicWall SSLVPN SMA100 SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-20016 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.

CVE-2021-20016 is a SQL injection vulnerability in SonicWall SSLVPN SMA100 appliances. An unauthenticated remote attacker can exploit it to gain access to credentials. This matters because SSL VPN gateways sit at the network edge and often hold or broker authentication material; successful abuse can lead to unauthorized access and has been associated with ransomware activity. Confirm all product and fix details against the vendor advisory.

How it works

The flaw is classed as CWE-89 (SQL injection). In products of this type, user-supplied input reaches a database query without sufficient validation or parameterization. An unauthenticated attacker who can reach the affected SSL VPN interface may craft input that alters the intended query logic. Per the CISA summary, successful exploitation enables credential access. Exact request paths, parameters, and payload mechanics are not detailed here; treat any public proof-of-concept material cautiously and verify behavior only in controlled lab conditions against the vendor’s description.

Because the attack requires no prior authentication and targets a remotely reachable service, internet-exposed SMA100 instances are the primary concern. Credential theft can then support further lateral movement or account abuse inside the organization.

Am I affected? How to find it in your systems

SonicWall SSLVPN SMA100 appliances are typically deployed as dedicated hardware or virtual appliances providing remote-access VPN. Inventory steps:

Telemetry signs of possible exploitation are generic for SQL injection and credential abuse: unusual or malformed requests to the VPN portal, spikes in database or application errors on the appliance, unexpected authentication successes or account lockouts, and subsequent anomalous VPN sessions or administrative logins. Forward appliance logs to a SIEM and alert on anomalies; specifics of exploit signatures must be validated against vendor or trusted threat-intel guidance.

How to remediate

Patch first. Apply the updates specified by SonicWall for the SMA100 SSL VPN platform exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions. After patching:

These steps reduce both the injection surface and the value of any credentials an attacker might have obtained.

If you can't patch immediately

Implement compensating controls until the vendor update can be applied:

These measures lower likelihood and impact but are not substitutes for the official patch.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently precede broader compromise and data theft. If you suspect exploitation, treat credential material and any data reachable via the VPN as potentially exposed: isolate affected systems, rotate secrets, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach datasets to check whether associated accounts appear in public breach corpora and then prioritize further monitoring or resets accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SSLVPN SMA100
WeaknessCWE-89
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities