CVE-2021-20021
SonicWall Email Security Improper Privilege Management Vulnerability
Record summary
CVE-2021-20021 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2021-20021 in KEV and reports its use in known ransomware campaigns.
Description
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Apr 20, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · CISA
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 20, 2021 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Email SecurityBrowse SonicWall / Email Security | CVE List | 10.0.9 and earlier | affected |
SonicWall Email SecurityBrowse SonicWall / SonicWall Email Security | CISA | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubSUPRAAA-1337/CVE-2021-20021Repository PoCby SUPRAAA-1337Stars: 2Not analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALSonicWall Email Security <= 10.0.9.x - Unauthenticated Admin Account CreationCVSS 9.8
SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Impact
Attackers can create admin accounts remotely, leading to full control over the email security system.
Remediation
Update to the latest version of SonicWall Email Security or apply security patches provided by SonicWall.
Source: ProjectDiscovery