Executive brief
SonicWall Email Security contains a path traversal vulnerability (CWE-22) that allows a post-authenticated attacker to read arbitrary files on the remote host. This vulnerability has been observed in the wild as part of an exploit chain to achieve privilege escalation.
Affected products
- SonicWall Email Security up to (excluding) 10.0.9.6173
- SonicWall Hosted Email Security up to (excluding) 10.0.9.6173
- SonicWall Email Security Virtual Appliance up to (excluding) 10.0.9.6177
- SonicWall Email Security Appliance 3300/4300/5000/5050/7000/7050/8300/9000 Firmware up to (excluding) 10.0.9.6177
Timeline
- 2021-04-23: disclosed: Initial NIST analysis and disclosure
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: Publication date of the advisory summary