CVE-2021-20021
KEV ransomwarelargeImproper Privilege Management in SonicWall Email Security 10.0.9.x Grants Admin Access
CISA: SonicWall Email Security Improper Privilege Management Vulnerability
CVE-2021-20021 is an improper privilege management flaw (CWE-269) in SonicWall Email Security version 10.0.9.x. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the vulnerable host, which allows the attacker to create a new administrative account on the Email Security instance. That administrative access gives an attacker full control over the email security platform (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling persistence, manipulation of email filtering, and a foothold from which to target downstream mail infrastructure. Any organization running SonicWall Email Security 10.0.9.x is affected, whether on hardware appliances (3300, 4300, 5050, 7050, 8300, 9000, 5000, 7000), as a virtual appliance, or via the hosted service. The flaw is being actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (headlines tie SonicWall email appliance attacks to the HelloKitty gang), and EPSS estimates an 83.4% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade SonicWall Email Security from 10.0.9.x to the latest patched release per SonicWall's instructions, as required by CISA KEV. Audit the deployment for unrecognized administrative accounts created by attackers, review management-interface HTTP logs for suspicious requests, and restrict exposure of the management interface to trusted networks. Because this bug was one of three SonicWall zero-days actively exploited with known ransomware use (HelloKitty), also hunt for signs of compromise and follow-on ransomware activity.
| SonicWall Email Security | 10.0.9.x |
| SonicWall Email Security Appliance 3300 | Email Security 10.0.9.x |
| SonicWall Email Security Appliance 4300 | Email Security 10.0.9.x |
| SonicWall Email Security Appliance 5050 | Email Security 10.0.9.x |
| SonicWall Email Security Appliance 7050 | Email Security 10.0.9.x |
| SonicWall Email Security Appliance 8300 | Email Security 10.0.9.x |
| SonicWall Email Security Appliance 9000 | Email Security 10.0.9.x |
| SonicWall Email Security Appliance 5000 | Email Security 10.0.9.x |
| SonicWall Email Security Appliance 7000 | Email Security 10.0.9.x |
| SonicWall Email Security Virtual Appliance | Email Security 10.0.9.x |
| SonicWall Hosted Email Security | Email Security 10.0.9.x |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
- Affected
- SonicWall SonicWall Email Security
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- sonicwall
- Products
- email security, email security appliance 9000 firmware, email security appliance 3300 firmware, email security appliance 4300 firmware, email security appliance 8300 firmware, email security appliance 5000 firmware, email security appliance 7000 firmware, email security appliance 5050 firmware, email security appliance 7050 firmware, email security virtual appliance, hosted email security
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H