Record summary

CVE-2021-20021 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2021-20021 in KEV and reports its use in known ransomware campaigns.

Description

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Apr 20, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 20, 2021 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List10.0.9 and earlieraffected
CISAVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubSUPRAAA-1337/CVE-2021-20021Repository PoCby SUPRAAA-1337Stars: 2Not analyzed1 file

865 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALSonicWall Email Security <= 10.0.9.x - Unauthenticated Admin Account CreationCVSS 9.8

SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

Impact

Attackers can create admin accounts remotely, leading to full control over the email security system.

Remediation

Update to the latest version of SonicWall Email Security or apply security patches provided by SonicWall.

WeaknessesCWE-269
Authorspussycat0x
Template tagscvecve2021sonicwallemail-securityauth-bypasskevpassivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*
Shodan: product:"SonicWALL Email Security"

Source: ProjectDiscovery

References

3