CRITICAL CISA KEV

CVE-2021-20038

CVSS v3

9.8

CRITICAL

EPSS Score

94.3%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

CISA Known Exploited Vulnerability

Date Added
1/28/2022
Patch Due Date
2/11/2022
Ransomware Use
Known

Technical details

Published
12/8/2021

Frequently asked questions

What is CVE-2021-20038?

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

Is CVE-2021-20038 actively exploited?

Yes. CVE-2021-20038 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 2/11/2022.

What is the CVSS score for CVE-2021-20038?

CVE-2021-20038 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-20038 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.