Skip to content

Latest commit

 

History

History
18 lines (12 loc) · 984 Bytes

CVE-2021-20039.md

File metadata and controls

18 lines (12 loc) · 984 Bytes

Description

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

POC

Reference

Github