Junglewise Threat Intelligence

CVE-2021-20021: SonicWall Email Security Improper Privilege Management Vulnerability

CVE-2021-20021 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Sonicwall Email Security. Vendors: SonicWall.

Executive brief

SonicWall Email Security contains an improper privilege management vulnerability that allows an unauthenticated attacker to create an administrative account by sending a crafted HTTP request. This vulnerability has been observed in the wild as part of an exploit chain to achieve full privilege escalation.

Affected products

  • SonicWall Email Security up to (excluding) 10.0.9.6103
  • SonicWall Hosted Email Security up to (excluding) 10.0.9.6103
  • SonicWall Email Security Virtual Appliance up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 3300 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 4300 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 5000 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 5050 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 7000 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 7050 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 8300 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 9000 Firmware up to (excluding) 10.0.9.6105

Timeline

  • 2021-04-09: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Advisory published date provided in report summary

Related threats