CRITICAL

CVE-2021-20021

Sonicwall Email Security 2021-04-09 CVSS v3.1
CVSS
9.8
KEV

Description

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

Summary dbcve.org

Unauthenticated attacker can create administrative accounts in SonicWall Email Security version 10.0.9.x via crafted HTTP request, representing an authentication bypass leading to full privilege escalation.

Mitigation

Apply vendor-supplied patch or upgrade to a non-vulnerable version; restrict management interface exposure to trusted networks.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

88.67%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE