CVE-2021-20031
CVE-2021-20031
Vexday Risk Score
43Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 13.0%KEV nãoPoC públicaNuclei simMetasploit —Patch —
Lifecycle
12 Oct 2021Published on NVD
13 Oct 2021Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
Affected products
SonicWall · SonicOSpublic PoCs found — 2
cve_referencepacketstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.htmlunverifiedexploitdbwww.exploit-db.com/exploits/50414unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →