A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.html | Exploit Third Party Advisory VDB Entry |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0019 | Vendor Advisory |
http://packetstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.html | Exploit Third Party Advisory VDB Entry |
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0019 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
21 Nov 2024, 05:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/164502/Sonicwall-SonicOS-7.0-Host-Header-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0019 - Vendor Advisory |
Information
Published : 2021-10-12 23:15
Updated : 2024-11-21 05:45
NVD link : CVE-2021-20031
Mitre link : CVE-2021-20031
CVE.ORG link : CVE-2021-20031
JSON object : View
Products Affected
sonicwall
- tz500w
- nsa_4700
- nsa_9650
- nsa_4650
- nsa_2700
- nssp_12400
- sonicos
- tz600
- nsa_2650
- supermassive_e10800
- tz370w
- nsv_25
- nsa_3650
- nssp_15700
- tz300
- supermassive_e10400
- nsa_3700
- nssp_13700
- supermassive_9400
- tz270w
- nsv_1600
- soho_250w
- nsv_100
- supermassive_9800
- tz400
- nsa_6700
- tz470w
- nsv_50
- tz570
- tz300p
- nsa_5650
- nsv_800
- supermassive_9200
- tz370
- tz600p
- nsv_870
- nsa_9250
- tz350
- tz570w
- nsa_6650
- tz300w
- tz500
- tz400w
- tz270
- nsv_200
- nssp_12800
- supermassive_e10200
- nsv_270
- tz670
- nsv_300
- nsv_400
- nsv_10
- nsv_470
- soho_250
- tz350w
- tz570p
- supermassive_9600
- tz470
- nsa_9450
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')