HIGH

CVE-2021-20022

Sonicwall Email Security 2021-04-09 CVSS v3.1
CVSS
7.2
KEV

Description

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

Summary dbcve.org

A post-authenticated arbitrary file upload vulnerability exists in SonicWall Email Security version 10.0.9.x. An authenticated attacker can exploit this to upload arbitrary files to the remote host, potentially achieving remote code execution by uploading malicious web shells or other payloads.

Mitigation

Apply the vendor-provided patch or upgrade to a patched version of SonicWall Email Security. Additionally, restrict administrative access to trusted IP addresses and monitor for unauthorized file uploads.

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

16.51%
Probability of exploitation in next 30 days
96.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE