Executive brief
A security flaw in the SonicWall Email Security appliance could allow an authorized administrator to inadvertently or intentionally crash the system. This appliance is used to protect corporate email from threats like spam and phishing. If exploited, the email security service would become unresponsive, potentially disrupting email flow or management capabilities.
Technical details
An improper input validation vulnerability (CWE-20) exists in the SonicWall Email Security appliance. A remote attacker with high-level administrative privileges can provide specially crafted input that the system fails to process correctly, leading to a denial-of-service (DoS) condition where the application becomes unresponsive. The attack is carried out over the network but requires valid administrative credentials (PR:H). The vulnerability affects versions 10.0.34.8215, 10.0.34.8223, and earlier.
Affected products
- SonicWall Email Security 10.0.34.8215 and earlier, 10.0.34.8223 and earlier
Timeline
- 2026-03-31: disclosed
- 2026-03-31: advisory: SonicWall PSIRT published SNWLID-2026-0002