9.8
CVE-2021-20021
- EPSS 90.69%
- Veröffentlicht 09.04.2021 18:15:13
- Zuletzt bearbeitet 10.11.2025 19:04:58
- Quelle PSIRT@sonicwall.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Email Security Version < 10.0.9.6103
Sonicwall ≫ Email Security Appliance 9000 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Appliance 3300 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Appliance 4300 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Appliance 8300 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Appliance 5000 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Appliance 7000 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Appliance 5050 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Appliance 7050 Firmware Version < 10.0.9.6105
Sonicwall ≫ Email Security Virtual Appliance Version < 10.0.9.6105
Sonicwall ≫ Hosted Email Security Version < 10.0.9.6103
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
SonicWall Email Security Improper Privilege Management Vulnerability
SchwachstelleSonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 90.69% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.