Description
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
In plain language
AI Act nowCVE-2021-20022 is a file-upload weakness in SonicWall Email Security products that has been used in real ransomware activity, so most small businesses using these systems should act quickly—upgrade to the fixed versions.
CVE-2021-20022 is a post-authentication arbitrary file upload weakness in SonicWall Email Security (including hosted/email security appliances) that has been listed in CISA’s KEV and used in ransomware campaigns; attackers can upload arbitrary files to the remote host after gaining authenticated access.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-20022 and every CVE in our database. Create a free account — no credit card required.
Create Free Account