Hackers found leveraging three SonicWall zero-day vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20021 +1 in the same advisory: …20022 | Improper Privilege Management in SonicWall Email Security 10.0.9.x Grants Admin Access CVE-2021-20021 is an improper privilege management flaw (CWE-269) in SonicWall Email Security version 10.0.9.x. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the vulnerable host, which allows the attacker to create a new administrative account on the Email Security instance. That administrative access gives an attacker full control over the email security platform (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling persistence, manipulation of email filtering, and a foothold from which to target downstream mail infrastructure. Any organization running SonicWall Email Security 10.0.9.x is affected, whether on hardware appliances (3300, 4300, 5050, 7050, 8300, 9000, 5000, 7000), as a virtual appliance, or via the hosted service. The flaw is being actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (headlines tie SonicWall email appliance attacks to the HelloKitty gang), and EPSS estimates an 83.4% probability of exploitation within 30 days (100th percentile). Do: Upgrade SonicWall Email Security from 10.0.9.x to the latest patched release per SonicWall's instructions, as required by CISA KEV. Audit the deployment for unrecognized administrative accounts created by attackers, review management-interface HTTP logs for suspicious requests, and restrict exposure of the management interface to trusted networks. Because this bug was one of three SonicWall zero-days actively exploited with known ransomware use (HelloKitty), also hunt for signs of compromise and follow-on ransomware activity. | 9.8 group max | 83% | KEV ransomware |
| large≈ tens of thousands of deployments (order of 10k–100k systems) | |
| CVE-2021-20023 | Post-Auth Path Traversal Arbitrary File Read in SonicWall Email Security 10.0.9.x CVE-2021-20023 is a path traversal flaw (CWE-22) in SonicWall Email Security version 10.0.9.x that allows an attacker who has already authenticated to the product to read arbitrary files on the remote host via a crafted request. Because it is network-exploitable, requires only high-privileged (admin-level) credentials, and needs no user interaction, it is typically triggered with an administrator account or credentials compromised by an attacker. Successful exploitation exposes sensitive file contents, potentially including configuration data or credentials that enable follow-on compromise, and CISA notes known ransomware use. It affects organizations running SonicWall Email Security on hardware appliances (3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000), the virtual appliance, and the hosted service. The flaw is being actively exploited: it was added to the CISA KEV on 2021-11-03 and headlines describe it as one of three zero-days actively exploited in SonicWall Email Security products in the wild. Do: Upgrade all Email Security deployments (hardware appliances, virtual appliance, hosted) off the vulnerable 10.0.9.x line to SonicWall's patched release per the vendor's instructions. Because exploitation requires authenticated admin access, restrict the management interface to trusted admin networks or VPN, review and rotate administrator credentials, and check for signs of compromise (unexpected admin logins, unusual file reads) given the known ransomware use. Prioritize patching internet-reachable appliances, as the flaw is listed in the CISA KEV and federal remediation is required. | 4.9 | 51% | KEV ransomware |
| largeroughly tens of thousands of appliance/virtual-appliance deployments plus hosted tenants (order-of-magnitude estimate) |
Full article450 words · extracted from helpnetsecurity.com · click to collapse
Attackers that seem to have “intimate knowledge” of the SonicWall Email Security product have been discovered leveraging three (at the time) zero-day vulnerabilities in the popular enterprise solution.

Exploited in conjunction, the flaws allowed the attacker to obtain administrative access and code execution on a SonicWall ES device, then install a backdoor, access files and emails, and move laterally into the victim organization’s network.
The SonicWall Email Security zero-day vulnerabilities and the discovered attack
The three vulnerabilities in question are:
- CVE-2021-20021, which allowed attackers to create an unauthorized administrative account by sending a crafted HTTP request to the remote host
- CVE-2021-20022, which allowed post-authenticated attackers to upload arbitrary files to the remote host
- CVE-2021-20023, which allowed post-authenticated attackers to read arbitrary files from the remote host
“In March 2021, Mandiant Managed Defense identified post-exploitation web shell activity on an internet-accessible system within a customer’s environment. Managed Defense isolated the system and collected evidence to determine how the system was compromised,” Mandiant/FireEye researchers shared.
“The system was quickly identified as a SonicWall Email Security (ES) application running on a standard Windows Server 2012 installation. The adversary-installed web shell was being served through the HTTPS-enabled Apache Tomcat web server bundled with SonicWall ES. Due to the web shell being served in the application’s bundled web server, we immediately suspected the compromise was associated with the SonicWall ES application itself.”
An in-depth investigation revealed that the SonicWall ES installation was up-to-date and that the attackers tried to hide their presence by deleting application-level log entries.
They managed to upload malicious files (the BEHINDER web shell) on the host system and retrieve sensitive configuration files from it, which contained details about existing accounts and Active Directory credentials used by the application.
They used tools already present on the system to recover password hashes and LSA secrets and collect and compress daily archives of emails processed by the solution.
A first bout of attacker activity was followed by a second one several days later, when they leveraged the obtained credentials to move laterally on the network, access a variety of other hosts and, essentially, perform reconnaissance. Fortunately, their activities have been noticed and cut short, so their ultimate goal remains unknown.
Some of the actions the attackers effected demonstrate their familiarity with the innards of the SonicWall Email Security solution and their skill at employing tactics to hide their presence from defenders.
Patches are available
The vulnerabilities affect SonicWall Email Security hardware appliances, virtual appliances and software installations on Microsoft Windows Server. The affected versions are listed in SonicWall’s security notice.
Patched versions are available for all except legacy versions that are no longer supported, and the company urges customers to upgrade immediately.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/04/21/sonicwall-email-security-zero-day-vulnerabilities/