CRITICAL
CVE-2021-20021
CVSS
9.8
KEV
Description
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Summary dbcve.org
Unauthenticated attacker can create administrative accounts in SonicWall Email Security version 10.0.9.x via crafted HTTP request, representing an authentication bypass leading to full privilege escalation.
Mitigation
Apply vendor-supplied patch or upgrade to a non-vulnerable version; restrict management interface exposure to trusted networks.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
88.67%
Probability of exploitation in next 30 days
99.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.