LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-20028: SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 28, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 18, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-20028 to its Known Exploited Vulnerabilities catalog on Mar 28, 2022, with a federal patch deadline of Apr 18, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.

CVE-2021-20028 is a SQL injection vulnerability in SonicWall Secure Remote Access (SRA) products. It stems from improper neutralization of SQL commands, allowing an attacker who can reach the affected interface to interfere with backend database queries. This matters because SRA appliances are commonly exposed for remote access; successful abuse can lead to unauthorized data access or further compromise, and the issue has been associated with ransomware activity. The product line is end-of-life, so organizations still running it face elevated risk.

How it works

The weakness is CWE-89: improper neutralization of special elements used in an SQL command. In products of this class, user-supplied input is incorporated into database queries without adequate sanitization or parameterization. An attacker who can submit crafted input to a vulnerable endpoint may alter the intended query logic. Depending on the application’s database privileges and query structure, that can allow reading, modifying, or in some cases influencing data the application should not expose. Exact attack preconditions, reachable parameters, and impact depend on the specific SRA build and configuration; confirm those details only against the vendor advisory. No exploit mechanics beyond the CWE class are assumed here.

Am I affected? How to find it in your systems

SonicWall SRA appliances are typically deployed as remote-access gateways, often reachable from the internet or partner networks to support VPN or portal access. Inventory any SonicWall hardware or virtual appliances used for secure remote access, including devices that may have been left in place after migration to newer platforms.

How to remediate

CISA’s required action is clear: the impacted product is end-of-life and should be disconnected if still in use. Prioritize removal from production rather than seeking a long-term patch path on unsupported hardware.

If you can't patch immediately

Unsupported products cannot be reliably patched. Until you can disconnect:

Plan immediate replacement; compensating controls only reduce—not eliminate—risk on end-of-life gear known to be tied to ransomware use.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently precede data theft or encryption events. If this appliance was reachable and unpatched, assume an attacker may have accessed data or credentials handled by the SRA. Follow your incident-response process: isolate, preserve evidence, assess scope, and notify stakeholders as required. As one quick check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts already appear in public compilations.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · Secure Remote Access (SRA)
WeaknessCWE-89
Added to CISA KEVMar 28, 2022
Federal patch deadlineApr 18, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities