cve/2021/CVE-2021-20039.md
2024-06-18 02:51:15 +02:00

1.0 KiB

CVE-2021-20039

Description

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

POC

Reference

Github