CVE-2021-20022High· 7.2▾ Abyssal⚠ Exploited in the wildSonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 39.6 · likelihood 3.3 · exploitation 25 · ransomware 5
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Nov 17, 2021
Last analysed / modified upstream
17%
Added to the CISA catalog on Nov 3, 2021. Federal remediation due Nov 17, 2021. View catalog ↗
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
email_security < 10.0.9.6103email_security_appliance_9000_firmware < 10.0.9.6105email_security_appliance_3300_firmware < 10.0.9.6105email_security_appliance_4300_firmware < 10.0.9.6105email_security_appliance_8300_firmware < 10.0.9.6105email_security_appliance_5000_firmware < 10.0.9.6105email_security_appliance_7000_firmware < 10.0.9.6105email_security_appliance_5050_firmware < 10.0.9.6105email_security_appliance_7050_firmware < 10.0.9.6105email_security_virtual_appliance < 10.0.9.6105hosted_email_security < 10.0.9.6103Upgrade past the affected range:
email_security 10.0.9.6103email_security_appliance_9000_firmware 10.0.9.6105email_security_appliance_3300_firmware 10.0.9.6105email_security_appliance_4300_firmware 10.0.9.6105email_security_appliance_8300_firmware 10.0.9.6105email_security_appliance_5000_firmware 10.0.9.6105email_security_appliance_7000_firmware 10.0.9.6105email_security_appliance_5050_firmware 10.0.9.6105email_security_appliance_7050_firmware 10.0.9.6105email_security_virtual_appliance 10.0.9.6105hosted_email_security 10.0.9.6103Connected by shared product, vendor, weakness, or advisory.
CVE-2024-50623Critical· 9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
CVE-2021-20023Medium· 4.9SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
CVE-2021-20021Critical· 9.8A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2017-12617High· 8.1When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g
CVE-2017-11357Critical· 9.8Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVE-2017-12615High· 8.1When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g