CVE-2021-20022
KEV ransomwaremoderatePost-Auth Arbitrary File Upload in SonicWall Email Security 10.0.9.x
CISA: SonicWall Email Security Unrestricted Upload of File Vulnerability
SonicWall Email Security version 10.0.9.x contains an unrestricted file upload flaw (CWE-434) that allows a post-authenticated attacker to upload arbitrary files to the remote host. The flaw is reachable over the network but requires high-level privileges (CVSS 3.1 vector notes PR:H), so an attacker needs valid privileged access to the email security platform before they can abuse it. Successful exploitation lets the attacker place arbitrary files on the appliance or service, which can be leveraged toward further compromise; the associated campaign against SonicWall email appliances is known to have escalated to ransomware deployment. Any organization running SonicWall Email Security on version 10.0.9.x is affected, including the hardware appliance models (3300, 4300, 5000, 5050, 7000, 7050, 8300, 9000), the virtual appliance, and the hosted service. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, as part of a broader campaign attacking SonicWall email appliances with multiple zero-days.
What to do: Apply the vendor's patched SonicWall Email Security release per SonicWall's update instructions and verify that hosted instances have been updated by the vendor; prioritize patching since the flaw is on CISA's KEV list with known ransomware use. Restrict management-interface access to trusted networks, rotate credentials for privileged Email Security accounts, and hunt for signs of compromise such as unexpected uploaded files, new administrative accounts, and ransomware indicators on appliances still running 10.0.9.x.
| SonicWall Email Security | 10.0.9.x |
| SonicWall Email Security Appliance 3300 firmware | 10.0.9.x |
| SonicWall Email Security Appliance 4300 firmware | 10.0.9.x |
| SonicWall Email Security Appliance 5000 firmware | 10.0.9.x |
| SonicWall Email Security Appliance 5050 firmware | 10.0.9.x |
| SonicWall Email Security Appliance 7000 firmware | 10.0.9.x |
| SonicWall Email Security Appliance 7050 firmware | 10.0.9.x |
| SonicWall Email Security Appliance 8300 firmware | 10.0.9.x |
| SonicWall Email Security Appliance 9000 firmware | 10.0.9.x |
| SonicWall Email Security Virtual Appliance | 10.0.9.x |
| SonicWall Hosted Email Security | 10.0.9.x |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
- Affected
- SonicWall SonicWall Email Security
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- sonicwall
- Products
- email security, email security appliance 9000 firmware, email security appliance 3300 firmware, email security appliance 4300 firmware, email security appliance 8300 firmware, email security appliance 5000 firmware, email security appliance 7000 firmware, email security appliance 5050 firmware, email security appliance 7050 firmware, email security virtual appliance, hosted email security
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H