CVE Tools

Description

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

In plain language

AI Act now

CVE-2021-20023 is a SonicWall Email Security flaw where a logged-in attacker can read any file on the system, and since it was used in real ransomware activity, RED means small businesses should act now by updating to the fixed versions.

Executive summary

CVE-2021-20023 is a post-authenticated arbitrary file read in SonicWall Email Security (and related appliances/hosted services) caused by improper input validation, enabling an attacker with valid credentials to read arbitrary server files; it is listed in the CISA KEV and was used in ransomware campaigns.

If affected, business impact
Sensitive data theft from serverPossible takeover of sensitive systemsRansomware enablement via stolen dataOperational disruption

What to do now

  1. Check your deployment type (Email Security, Hosted Email Security, Email Security Appliance firmware, or Email Security Virtual Appliance) and identify your exact version (10.0.9.x and whether you have any .xxxx build listed).
  2. If you are on SonicWall Email Security 10.0.9.x, plan an immediate upgrade to the fixed build for your product.
  3. Upgrade to the fixed version(s): Email Security → 10.0.9.6173; Email Security Appliance (9000/3300/4300/8300/5000/7000/5050/7050) and Email Security Virtual Appliance → 10.0.9.6177; Hosted Email Security → 10.0.9.6173.
  4. After upgrading, confirm the system now reports the expected fixed version and that the email security services are healthy, then review authentication logs for suspicious authenticated activity around the time of any attempted access.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:HUI:NS:UC:HI:NA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:HPrivileges Required
High
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:NIntegrity
None
A:NAvailability
None

Weaknesses

Affected Products

and 5 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Nov 3, 2021
Remediation due:Nov 17, 2021
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Collection
Discovery
View detailed technique mapping

References

and 2 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2021-20023 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows