Junglewise Threat Intelligence

CVE-2021-20023: SonicWall Email Security Path Traversal Vulnerability

CVE-2021-20023 · Severity: critical · CVSS 4.9 · Exploited in the wild · Published 2021-11-03

Technologies: SonicWall Email Security. Vendors: SonicWall.

Executive brief

SonicWall Email Security contains a path traversal vulnerability (CWE-22) that allows a post-authenticated attacker to read arbitrary files on the remote host. This vulnerability has been observed in the wild as part of an exploit chain to achieve privilege escalation.

Affected products

  • SonicWall Email Security up to (excluding) 10.0.9.6173
  • SonicWall Hosted Email Security up to (excluding) 10.0.9.6173
  • SonicWall Email Security Virtual Appliance up to (excluding) 10.0.9.6177
  • SonicWall Email Security Appliance 3300/4300/5000/5050/7000/7050/8300/9000 Firmware up to (excluding) 10.0.9.6177

Timeline

  • 2021-04-23: disclosed: Initial NIST analysis and disclosure
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Publication date of the advisory summary

Related threats