A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
📦
nsa_2650
Vendor: sonicwall
Actively Exploited
1
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
9
Remote Access
Total CVEs
24
Total Indexed
Avg. EPSS
2.04%
Exploit Prob.
Security Vulnerability Index
Page 3 / 3
6.1
CVSS
CVE-2021-20031
Exploit Found
Severity: MEDIUM
7.5
CVSS
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted request. This vulnerability affects SonicOS Gen5, Gen6, Gen7 platforms, and SonicOSv virtual firewalls.
Severity: HIGH
5.4
CVSS
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
Severity: MEDIUM
5.4
CVSS
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
Severity: MEDIUM