ZeroHour

CVE-2021-20021

KEV ransomwarelarge

Improper Privilege Management in SonicWall Email Security 10.0.9.x Grants Admin Access

CISA: SonicWall Email Security Improper Privilege Management Vulnerability

CVSS 3.1
9.8 critical
EPSS
83%p100
Published
()
KEV added
AI analysis

CVE-2021-20021 is an improper privilege management flaw (CWE-269) in SonicWall Email Security version 10.0.9.x. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the vulnerable host, which allows the attacker to create a new administrative account on the Email Security instance. That administrative access gives an attacker full control over the email security platform (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling persistence, manipulation of email filtering, and a foothold from which to target downstream mail infrastructure. Any organization running SonicWall Email Security 10.0.9.x is affected, whether on hardware appliances (3300, 4300, 5050, 7050, 8300, 9000, 5000, 7000), as a virtual appliance, or via the hosted service. The flaw is being actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (headlines tie SonicWall email appliance attacks to the HelloKitty gang), and EPSS estimates an 83.4% probability of exploitation within 30 days (100th percentile).

What to do: Upgrade SonicWall Email Security from 10.0.9.x to the latest patched release per SonicWall's instructions, as required by CISA KEV. Audit the deployment for unrecognized administrative accounts created by attackers, review management-interface HTTP logs for suspicious requests, and restrict exposure of the management interface to trusted networks. Because this bug was one of three SonicWall zero-days actively exploited with known ransomware use (HelloKitty), also hunt for signs of compromise and follow-on ransomware activity.

Affected
SonicWall Email Security10.0.9.x
SonicWall Email Security Appliance 3300Email Security 10.0.9.x
SonicWall Email Security Appliance 4300Email Security 10.0.9.x
SonicWall Email Security Appliance 5050Email Security 10.0.9.x
SonicWall Email Security Appliance 7050Email Security 10.0.9.x
SonicWall Email Security Appliance 8300Email Security 10.0.9.x
SonicWall Email Security Appliance 9000Email Security 10.0.9.x
SonicWall Email Security Appliance 5000Email Security 10.0.9.x
SonicWall Email Security Appliance 7000Email Security 10.0.9.x
SonicWall Email Security Virtual ApplianceEmail Security 10.0.9.x
SonicWall Hosted Email SecurityEmail Security 10.0.9.x
Estimated exposure
large≈ tens of thousands of deployments (order of 10k–100k systems) — No install counts are provided in the data, so this is an order-of-magnitude estimate based on SonicWall's enterprise footprint across hardware appliances, virtual appliances, and a hosted service, whose management interfaces are commonly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

CISA Known Exploited Vulnerability
Affected
SonicWall SonicWall Email Security
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
email security, email security appliance 9000 firmware, email security appliance 3300 firmware, email security appliance 4300 firmware, email security appliance 8300 firmware, email security appliance 5000 firmware, email security appliance 7000 firmware, email security appliance 5050 firmware, email security appliance 7050 firmware, email security virtual appliance, hosted email security
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news