ZeroHour

CVE-2021-20022

KEV ransomwaremoderate

Post-Auth Arbitrary File Upload in SonicWall Email Security 10.0.9.x

CISA: SonicWall Email Security Unrestricted Upload of File Vulnerability

CVSS 3.1
7.2 high
EPSS
17%p97
Published
()
KEV added
AI analysis

SonicWall Email Security version 10.0.9.x contains an unrestricted file upload flaw (CWE-434) that allows a post-authenticated attacker to upload arbitrary files to the remote host. The flaw is reachable over the network but requires high-level privileges (CVSS 3.1 vector notes PR:H), so an attacker needs valid privileged access to the email security platform before they can abuse it. Successful exploitation lets the attacker place arbitrary files on the appliance or service, which can be leveraged toward further compromise; the associated campaign against SonicWall email appliances is known to have escalated to ransomware deployment. Any organization running SonicWall Email Security on version 10.0.9.x is affected, including the hardware appliance models (3300, 4300, 5000, 5050, 7000, 7050, 8300, 9000), the virtual appliance, and the hosted service. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, as part of a broader campaign attacking SonicWall email appliances with multiple zero-days.

What to do: Apply the vendor's patched SonicWall Email Security release per SonicWall's update instructions and verify that hosted instances have been updated by the vendor; prioritize patching since the flaw is on CISA's KEV list with known ransomware use. Restrict management-interface access to trusted networks, rotate credentials for privileged Email Security accounts, and hunt for signs of compromise such as unexpected uploaded files, new administrative accounts, and ransomware indicators on appliances still running 10.0.9.x.

Affected
SonicWall Email Security10.0.9.x
SonicWall Email Security Appliance 3300 firmware10.0.9.x
SonicWall Email Security Appliance 4300 firmware10.0.9.x
SonicWall Email Security Appliance 5000 firmware10.0.9.x
SonicWall Email Security Appliance 5050 firmware10.0.9.x
SonicWall Email Security Appliance 7000 firmware10.0.9.x
SonicWall Email Security Appliance 7050 firmware10.0.9.x
SonicWall Email Security Appliance 8300 firmware10.0.9.x
SonicWall Email Security Appliance 9000 firmware10.0.9.x
SonicWall Email Security Virtual Appliance10.0.9.x
SonicWall Hosted Email Security10.0.9.x
Estimated exposure
moderate≈10,000+ deployments worldwide, with several thousand directly internet-exposed — Public internet scans at the time of the disclosure campaign showed thousands of exposed SonicWall Email Security instances, and because this is a per-organization email gateway typically deployed as an appliance or virtual appliance by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

CISA Known Exploited Vulnerability
Affected
SonicWall SonicWall Email Security
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
email security, email security appliance 9000 firmware, email security appliance 3300 firmware, email security appliance 4300 firmware, email security appliance 8300 firmware, email security appliance 5000 firmware, email security appliance 7000 firmware, email security appliance 5050 firmware, email security appliance 7050 firmware, email security virtual appliance, hosted email security
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news