CVE-2021-20023KEV · OVERDUECWE-22path-traversal

SonicWall Email Security Path Traversal Vulnerability

Medium · published April 20, 2021

Patch now

The score understates this — it's already being exploited

CVSS calls it medium at 4.9. It is confirmed in active exploitation. It sits in the 98.9th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
4.9
EPSS
51%
Percentile
98.9
In the wild
Confirmed
What it is

⚠️ A post-authenticated attacker can read any file on your SonicWall Email Security system! It's like letting a mischievous guest grab whatever they want from your private stash after check-in. 📂 Think of your email security system as a hotel room. Once someone checks in and gets the key, they shouldn’t have access to your personal belongings, right? But in this case, a clever guest sneaks in and rummages through your documents without permission. If an attacker exploits this vulnerability, they could read sensitive files on the server that should remain private, potentially accessing confidential information like customer data or internal communications. This could lead to data breaches, compliance issues, and a loss of trust from clients — a situation that's far from ideal!

Put simply

Think of your email security system as a hotel room. Once someone checks in and gets the key, they shouldn’t have access to your personal belongings, right? But in this case, a clever guest sneaks in and rummages through your documents without permission. This vulnerability in SonicWall Email Security version 10.0.9.x allows an attacker with valid credentials to bypass restrictions and access arbitrary files on the remote host, putting sensitive information at risk.

What to do

If an attacker exploits this vulnerability, they could read sensitive files on the server that should remain private, potentially accessing confidential information like customer data or internal communications. This could lead to data breaches, compliance issues, and a loss of trust from clients — a situation that's far from ideal! To protect your system, patch to the latest version of SonicWall Email Security as soon as possible. Conduct a security audit to identify any unusual activity and consider revising user permissions to limit access to sensitive files. 🔒 You've got this! Follow these steps, and you'll be one step closer to securing your email environment! 🛡️

The record
Technical detail
CVSS v3.1
4.9 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.51407 · 98.9th percentile
Weakness
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Published
2021-04-20T16:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (11)
ProductVersionsFixed in
sonicwall/email_security< 10.0.9.617310.0.9.6173
sonicwall/email_security_appliance_9000_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_appliance_3300_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_appliance_4300_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_appliance_8300_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_appliance_5000_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_appliance_7000_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_appliance_5050_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_appliance_7050_firmware< 10.0.9.617710.0.9.6177
sonicwall/email_security_virtual_appliance< 10.0.9.617710.0.9.6177
sonicwall/hosted_email_security< 10.0.9.617310.0.9.6173
References (3)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 20 APR 11:55Z
    SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host
    cvelistv5