CVE-2021-20021
CRITICAL KEV RANSOMWARE NUCLEISonicwall Email Security < 10.0.9.6103 - Improper Privilege Management
Title source: ruleDescription
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Exploits (1)
Nuclei Templates (1)
SonicWall Email Security <= 10.0.9.x - Unauthenticated Admin Account Creation
CRITICALVERIFIEDby pussycat0x
Shodan:
product:"SonicWALL Email Security"
Scores
CVSS v3
9.8
EPSS
0.9170
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-04-20
InTheWild.io
2021-04-20
ENISA EUVD
EUVD-2021-7484
Ransomware Use
Confirmed
CWE
CWE-269
Status
published
Products (11)
sonicwall/email_security
< 10.0.9.6103
sonicwall/email_security_appliance_3300_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_4300_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_5000_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_5050_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_7000_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_7050_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_8300_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_9000_firmware
< 10.0.9.6105
sonicwall/email_security_virtual_appliance
< 10.0.9.6105
... and 1 more
Published
Apr 09, 2021
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026