ZeroHour

CVE-2021-20023

KEV ransomwarelarge

Post-Auth Path Traversal Arbitrary File Read in SonicWall Email Security 10.0.9.x

CISA: SonicWall Email Security Path Traversal Vulnerability

CVSS 3.1
4.9 medium
EPSS
51%p99
Published
()
KEV added
AI analysis

CVE-2021-20023 is a path traversal flaw (CWE-22) in SonicWall Email Security version 10.0.9.x that allows an attacker who has already authenticated to the product to read arbitrary files on the remote host via a crafted request. Because it is network-exploitable, requires only high-privileged (admin-level) credentials, and needs no user interaction, it is typically triggered with an administrator account or credentials compromised by an attacker. Successful exploitation exposes sensitive file contents, potentially including configuration data or credentials that enable follow-on compromise, and CISA notes known ransomware use. It affects organizations running SonicWall Email Security on hardware appliances (3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000), the virtual appliance, and the hosted service. The flaw is being actively exploited: it was added to the CISA KEV on 2021-11-03 and headlines describe it as one of three zero-days actively exploited in SonicWall Email Security products in the wild.

What to do: Upgrade all Email Security deployments (hardware appliances, virtual appliance, hosted) off the vulnerable 10.0.9.x line to SonicWall's patched release per the vendor's instructions. Because exploitation requires authenticated admin access, restrict the management interface to trusted admin networks or VPN, review and rotate administrator credentials, and check for signs of compromise (unexpected admin logins, unusual file reads) given the known ransomware use. Prioritize patching internet-reachable appliances, as the flaw is listed in the CISA KEV and federal remediation is required.

Affected
SonicWall Email Security10.0.9.x
SonicWall Email Security Appliance (models 3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000) firmware10.0.9.x
SonicWall Email Security Virtual Appliance10.0.9.x
SonicWall Hosted Email Security10.0.9.x
Estimated exposure
largeroughly tens of thousands of appliance/virtual-appliance deployments plus hosted tenants (order-of-magnitude estimate) — This is an enterprise email-security product deployed per organization across appliance, virtual-appliance and hosted variants; public internet scans of SonicWall Email Security management interfaces have historically shown only thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

CISA Known Exploited Vulnerability
Affected
SonicWall SonicWall Email Security
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sonicwall
Products
email security, email security appliance 9000 firmware, email security appliance 3300 firmware, email security appliance 4300 firmware, email security appliance 8300 firmware, email security appliance 5000 firmware, email security appliance 7000 firmware, email security appliance 5050 firmware, email security appliance 7050 firmware, email security virtual appliance, hosted email security
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news