Showing 5 vulnerabilities on this page for SonicWall Email Security

Signals CISA KEV Ransomware Nuclei
SonicWall vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses.

CWE-209Feb 14, 2023
CVSS5.3v3.1EPSS0.717%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions

CWE-290CWE-358Jul 29, 2022
CVSS7.5v3.1EPSS0.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SonicWall Email Security Path Traversal Vulnerability

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

CWE-22Apr 20, 2021
CVSS4.9v3.1EPSS50.2%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

SonicWall Email Security Unrestricted Upload of File Vulnerability

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

CWE-434Apr 9, 2021
CVSS7.2v3.1EPSS16.5%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

SonicWall Email Security Improper Privilege Management Vulnerability

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

CWE-269CWE-306Apr 9, 20211 related artifact
CVSS9.8v3.1EPSS83.4%PoCs1SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX