CVE-2021-20022
HIGH KEV RANSOMWARESonicwall Email Security < 10.0.9.6103 - Unrestricted File Upload
Title source: ruleDescription
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Scores
CVSS v3
7.2
EPSS
0.2002
EPSS Percentile
95.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2021-04-20
InTheWild.io
2021-04-20
ENISA EUVD
EUVD-2021-7485
Ransomware Use
Confirmed
CWE
CWE-434
Status
published
Products (11)
sonicwall/email_security
< 10.0.9.6103
sonicwall/email_security_appliance_3300_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_4300_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_5000_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_5050_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_7000_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_7050_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_8300_firmware
< 10.0.9.6105
sonicwall/email_security_appliance_9000_firmware
< 10.0.9.6105
sonicwall/email_security_virtual_appliance
< 10.0.9.6105
... and 1 more
Published
Apr 09, 2021
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026