Medium · published April 20, 2021
CVSS calls it medium at 4.9. It is confirmed in active exploitation. It sits in the 98.9th percentile for exploit probability.
⚠️ A post-authenticated attacker can read any file on your SonicWall Email Security system! It's like letting a mischievous guest grab whatever they want from your private stash after check-in. 📂 Think of your email security system as a hotel room. Once someone checks in and gets the key, they shouldn’t have access to your personal belongings, right? But in this case, a clever guest sneaks in and rummages through your documents without permission. If an attacker exploits this vulnerability, they could read sensitive files on the server that should remain private, potentially accessing confidential information like customer data or internal communications. This could lead to data breaches, compliance issues, and a loss of trust from clients — a situation that's far from ideal!
Think of your email security system as a hotel room. Once someone checks in and gets the key, they shouldn’t have access to your personal belongings, right? But in this case, a clever guest sneaks in and rummages through your documents without permission. This vulnerability in SonicWall Email Security version 10.0.9.x allows an attacker with valid credentials to bypass restrictions and access arbitrary files on the remote host, putting sensitive information at risk.
If an attacker exploits this vulnerability, they could read sensitive files on the server that should remain private, potentially accessing confidential information like customer data or internal communications. This could lead to data breaches, compliance issues, and a loss of trust from clients — a situation that's far from ideal! To protect your system, patch to the latest version of SonicWall Email Security as soon as possible. Conduct a security audit to identify any unusual activity and consider revising user permissions to limit access to sensitive files. 🔒 You've got this! Follow these steps, and you'll be one step closer to securing your email environment! 🛡️
| Product | Versions | Fixed in |
|---|---|---|
| sonicwall/email_security | < 10.0.9.6173 | 10.0.9.6173 |
| sonicwall/email_security_appliance_9000_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_appliance_3300_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_appliance_4300_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_appliance_8300_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_appliance_5000_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_appliance_7000_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_appliance_5050_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_appliance_7050_firmware | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/email_security_virtual_appliance | < 10.0.9.6177 | 10.0.9.6177 |
| sonicwall/hosted_email_security | < 10.0.9.6173 | 10.0.9.6173 |