CVE-2021-20022KEV · OVERDUECWE-434unrestricted-file-upload

SonicWall Email Security Unrestricted Upload of File Vulnerability

High · published April 9, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 7.2. It is confirmed in active exploitation. It sits in the 96.8th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
7.2
EPSS
17%
Percentile
96.8
In the wild
Confirmed
What it is

🚨 Just one logged-in user can turn a SonicWall Email Security instance into their personal upload station! 🔥 Think of it like a hotel that lets guests not only check in but also wander around to drop off any kind of package they want in the lobby. If no one is checking what’s being left behind, it could lead to all sorts of trouble! An attacker with a valid account could easily upload malicious files, potentially leading to data breaches or further exploitation within the network. This could allow them to plant backdoors or exfiltrate sensitive information, turning the situation absolutely devastating!

Put simply

Think of it like a hotel that lets guests not only check in but also wander around to drop off any kind of package they want in the lobby. If no one is checking what’s being left behind, it could lead to all sorts of trouble! This vulnerability in SonicWall Email Security version 10.0.9.x allows authenticated users to upload arbitrary files, bypassing necessary security controls that should prevent such actions.

What to do

An attacker with a valid account could easily upload malicious files, potentially leading to data breaches or further exploitation within the network. This could allow them to plant backdoors or exfiltrate sensitive information, turning the situation absolutely devastating! Immediately upgrade to the latest version of SonicWall Email Security to patch this vulnerability. Additionally, review user access levels and tighten permissions to ensure only necessary accounts have upload capabilities. Last but not least, regularly audit your file upload processes! You’ve got this! Stay proactive and secure your systems to keep those pesky attackers at bay! 🛡️

The record
Technical detail
CVSS v3.1
7.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.16509 · 96.8th percentile
Weakness
CWE-434 · Unrestricted Upload of File with Dangerous Type
Published
2021-04-09T22:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (11)
ProductVersionsFixed in
sonicwall/email_security< 10.0.9.610310.0.9.6103
sonicwall/email_security_appliance_9000_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_appliance_3300_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_appliance_4300_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_appliance_8300_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_appliance_5000_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_appliance_7000_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_appliance_5050_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_appliance_7050_firmware< 10.0.9.610510.0.9.6105
sonicwall/email_security_virtual_appliance< 10.0.9.610510.0.9.6105
sonicwall/hosted_email_security< 10.0.9.610310.0.9.6103
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 09 APR 17:50Z
    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host
    cvelistv5