CVE-2021-20021Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableA vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 17.7 · exploitation 25 · ransomware 5
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Nov 17, 2021
Last analysed / modified upstream
83%
1 GitHub repo · Nuclei ×1
83% → 89%
Added to the CISA catalog on Nov 3, 2021. Federal remediation due Nov 17, 2021. View catalog ↗
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
email_security < 10.0.9.6103email_security_appliance_9000_firmware < 10.0.9.6105email_security_appliance_3300_firmware < 10.0.9.6105email_security_appliance_4300_firmware < 10.0.9.6105email_security_appliance_8300_firmware < 10.0.9.6105email_security_appliance_5000_firmware < 10.0.9.6105email_security_appliance_7000_firmware < 10.0.9.6105email_security_appliance_5050_firmware < 10.0.9.6105email_security_appliance_7050_firmware < 10.0.9.6105email_security_virtual_appliance < 10.0.9.6105hosted_email_security < 10.0.9.6103Upgrade past the affected range:
email_security 10.0.9.6103email_security_appliance_9000_firmware 10.0.9.6105email_security_appliance_3300_firmware 10.0.9.6105email_security_appliance_4300_firmware 10.0.9.6105email_security_appliance_8300_firmware 10.0.9.6105email_security_appliance_5000_firmware 10.0.9.6105email_security_appliance_7000_firmware 10.0.9.6105email_security_appliance_5050_firmware 10.0.9.6105email_security_appliance_7050_firmware 10.0.9.6105email_security_virtual_appliance 10.0.9.6105hosted_email_security 10.0.9.6103Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-20023Medium· 4.9SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
CVE-2021-20022High· 7.2SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
CVE-2024-40766Critical· 9.8An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash
CVE-2026-83549High· 7.8Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
CVE-2019-7481High· 7.5Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources
CVE-2024-53704Critical· 9.8An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.