HIGH
CVE-2021-20022
CVSS
7.2
KEV
Description
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Summary dbcve.org
A post-authenticated arbitrary file upload vulnerability exists in SonicWall Email Security version 10.0.9.x. An authenticated attacker can exploit this to upload arbitrary files to the remote host, potentially achieving remote code execution by uploading malicious web shells or other payloads.
Mitigation
Apply the vendor-provided patch or upgrade to a patched version of SonicWall Email Security. Additionally, restrict administrative access to trusted IP addresses and monitor for unauthorized file uploads.
Weakness (CWE)
CWE-434
Unrestricted File Upload
EPSS Score
16.51%
Probability of exploitation in next 30 days
96.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.