CVE-2022-20038
published 2022-02-09CVE-2022-20038: In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.12%
2.1th percentile
In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Issue ID: ALPS06183335.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f9wp-vh4x-jjw7: In ccu driver, there is a possible memory corruption due to an incorrect bounds check
ghsa_unreviewed·2022-02-11
CVE-2022-20038 [MEDIUM] CWE-119 GHSA-f9wp-vh4x-jjw7: In ccu driver, there is a possible memory corruption due to an incorrect bounds check
In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06183335; Issue ID: ALPS06183335.
CISA
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
cisa·2022-01-28·CVSS 9.8
CVE-2021-20038 [CRITICAL] CWE-121 SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
Vulnerability: SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
Affected: SonicWall SMA 100 Appliances
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-20038
Remediation Due Date: 2022-02-11
Suricata
ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)
suricata·2025-04-14·CVSS 9.8
CVE-2021-20042 [CRITICAL] ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)
ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/fileshare/sonicfiles/sonicfiles|3f|"; fast_pattern; content:"RacNumber|3d|25"; content:"Arg1|3d|"; pcre:"/^[a-z]+\x3a\x2f{2}/R"; reference:url,www.rapid7.com/blog/post/2022/01/11/cve-2021-20038-42-sonicwall-sma-100-multiple-vulnerabilities-fixed-2/; reference:cve,2021-20042; classtype:web-application-attack; sid:2061554; rev:1; metadata:affected_product SonicWall, attack_target Server, tls_state TLSDecrypt, created_at 2025_04_14, cve CVE_2021_20042, deployment Perimeter, deployment Internal,
Suricata
ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M1
suricata·2022-01-26·CVSS 9.8
CVE-2021-20038 [CRITICAL] ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M1
ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M1
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M1"; flow:established,to_server; urilen:>400; threshold: type threshold, track by_src, count 10, seconds 30; http.request_line; content:"GET /%"; startswith; pcre:"/^[a-zA-Z0-9]{2}[%a-zA-Z0-9]{9}(?P(?:[%a-zA-Z0-9]{3}){4})(?P=addr)/R"; content:"%64%b8%06%08"; within:55; fast_pattern; content:"?"; reference:cve,2021-20038; classtype:attempted-admin; sid:2034984; rev:2; metadata:attack_target Server, created_at 2022_01_26, cve CVE_2021_20038, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id
Suricata
ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M2
suricata·2022-01-26·CVSS 9.8
CVE-2021-20038 [CRITICAL] ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M2
ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M2
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT SonicWall SMA Stack-Based Buffer Overflow CVE-2021-20038 M2"; flow:established,to_server; urilen:>400; threshold: type threshold, track by_src, count 10, seconds 30; http.request_line; content:"GET /%"; startswith; pcre:"/^[a-zA-Z0-9]{2}[%a-zA-Z0-9]{9}(?P(?:[%a-zA-Z0-9]{3}){4})(?P=addr)/R"; content:"%08%b7%06%08"; within:55; fast_pattern; content:"?"; reference:cve,2021-20038; classtype:attempted-admin; sid:2034985; rev:2; metadata:attack_target Server, created_at 2022_01_26, cve CVE_2021_20038, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id
No public exploits indexed.
2022-02-09
Published