A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.html | Exploit Third Party Advisory VDB Entry |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0019 | Vendor Advisory |
http://packetstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.html | Exploit Third Party Advisory VDB Entry |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0019 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
21 Nov 2024, 05:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0019 - Vendor Advisory |
Information
Published : 2021-10-12 23:15
Updated : 2024-11-21 05:45
NVD link : CVE-2021-20031
Mitre link : CVE-2021-20031
CVE.ORG link : CVE-2021-20031
JSON object : View
Products Affected
sonicwall
- nsa_2700
- nsv_470
- supermassive_9600
- tz370w
- nsa_6650
- nsv_50
- tz470
- nsv_25
- nsa_3650
- tz270
- tz500w
- nssp_12800
- supermassive_e10800
- nsa_9450
- nsv_270
- nsa_4700
- tz600
- tz600p
- nsa_9650
- tz300
- tz670
- tz370
- nsv_400
- supermassive_9800
- tz400
- nsv_870
- nsv_800
- supermassive_9400
- tz570p
- supermassive_9200
- tz270w
- nssp_15700
- sonicos
- nsv_10
- tz300w
- tz500
- tz570
- nsv_1600
- nsa_6700
- tz570w
- nssp_13700
- nsv_100
- tz300p
- nsa_5650
- tz470w
- nsa_2650
- nsa_9250
- tz350w
- nsv_200
- nssp_12400
- tz400w
- tz350
- nsa_3700
- supermassive_e10200
- supermassive_e10400
- soho_250
- soho_250w
- nsa_4650
- nsv_300
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')