CVE-2021-20023
KEV ransomwarelargePost-Auth Path Traversal Arbitrary File Read in SonicWall Email Security 10.0.9.x
CISA: SonicWall Email Security Path Traversal Vulnerability
CVE-2021-20023 is a path traversal flaw (CWE-22) in SonicWall Email Security version 10.0.9.x that allows an attacker who has already authenticated to the product to read arbitrary files on the remote host via a crafted request. Because it is network-exploitable, requires only high-privileged (admin-level) credentials, and needs no user interaction, it is typically triggered with an administrator account or credentials compromised by an attacker. Successful exploitation exposes sensitive file contents, potentially including configuration data or credentials that enable follow-on compromise, and CISA notes known ransomware use. It affects organizations running SonicWall Email Security on hardware appliances (3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000), the virtual appliance, and the hosted service. The flaw is being actively exploited: it was added to the CISA KEV on 2021-11-03 and headlines describe it as one of three zero-days actively exploited in SonicWall Email Security products in the wild.
What to do: Upgrade all Email Security deployments (hardware appliances, virtual appliance, hosted) off the vulnerable 10.0.9.x line to SonicWall's patched release per the vendor's instructions. Because exploitation requires authenticated admin access, restrict the management interface to trusted admin networks or VPN, review and rotate administrator credentials, and check for signs of compromise (unexpected admin logins, unusual file reads) given the known ransomware use. Prioritize patching internet-reachable appliances, as the flaw is listed in the CISA KEV and federal remediation is required.
| SonicWall Email Security | 10.0.9.x |
| SonicWall Email Security Appliance (models 3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000) firmware | 10.0.9.x |
| SonicWall Email Security Virtual Appliance | 10.0.9.x |
| SonicWall Hosted Email Security | 10.0.9.x |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
- Affected
- SonicWall SonicWall Email Security
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- sonicwall
- Products
- email security, email security appliance 9000 firmware, email security appliance 3300 firmware, email security appliance 4300 firmware, email security appliance 8300 firmware, email security appliance 5000 firmware, email security appliance 7000 firmware, email security appliance 5050 firmware, email security appliance 7050 firmware, email security virtual appliance, hosted email security
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N