Junglewise Threat Intelligence

CVE-2021-20022: SonicWall Email Security Unrestricted Upload of File Vulnerability

CVE-2021-20022 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2021-11-03

Technologies: Sonicwall Email Security. Vendors: SonicWall.

Executive brief

SonicWall Email Security contains an unrestricted file upload vulnerability (CWE-434) that allows a post-authenticated attacker to upload arbitrary files to the remote host. This vulnerability has been observed in the wild as part of an exploit chain with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

Affected products

  • SonicWall Email Security up to (excluding) 10.0.9.6103
  • SonicWall Hosted Email Security up to (excluding) 10.0.9.6103
  • SonicWall Email Security Virtual Appliance up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 3300 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 4300 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 5000 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 5050 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 7000 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 7050 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 8300 Firmware up to (excluding) 10.0.9.6105
  • SonicWall Email Security Appliance 9000 Firmware up to (excluding) 10.0.9.6105

Timeline

  • 2021-04-09: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild

Related threats