CVE-2022-20042
published 2022-02-09CVE-2022-20042: In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.12%
2.3th percentile
In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06108487; Issue ID: ALPS06108487.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)
suricata·2025-04-14·CVSS 9.8
CVE-2021-20042 [CRITICAL] ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)
ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SERVER SonicWall SMA Unauthenticated sonicfiles Confused Deputy (CVE-2021-20042)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/fileshare/sonicfiles/sonicfiles|3f|"; fast_pattern; content:"RacNumber|3d|25"; content:"Arg1|3d|"; pcre:"/^[a-z]+\x3a\x2f{2}/R"; reference:url,www.rapid7.com/blog/post/2022/01/11/cve-2021-20038-42-sonicwall-sma-100-multiple-vulnerabilities-fixed-2/; reference:cve,2021-20042; classtype:web-application-attack; sid:2061554; rev:1; metadata:affected_product SonicWall, attack_target Server, tls_state TLSDecrypt, created_at 2025_04_14, cve CVE_2021_20042, deployment Perimeter, deployment Internal,
No public exploits indexed.
No writeups or analysis indexed.
2022-02-09
Published