TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2021-20022

HIGHCISA KEV
7.2

Beschreibung

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

CVE Details

CVSS v3.1 Bewertung7.2
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht4/9/2021
Zuletzt geandert11/10/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerSonicWall
ProduktSonicWall Email Security
SchwachstellennameSonicWall Email Security Unrestricted Upload of File Vulnerability
KEV Aufnahmedatum2021-11-03
Behebungsfrist2021-11-17
Ransomware-NutzungKnown

Betroffene Produkte

microsoft:windowssonicwall:email_securitysonicwall:email_security_appliance_3300sonicwall:email_security_appliance_3300_firmwaresonicwall:email_security_appliance_4300sonicwall:email_security_appliance_4300_firmwaresonicwall:email_security_appliance_5000sonicwall:email_security_appliance_5000_firmwaresonicwall:email_security_appliance_5050sonicwall:email_security_appliance_5050_firmwaresonicwall:email_security_appliance_7000sonicwall:email_security_appliance_7000_firmwaresonicwall:email_security_appliance_7050sonicwall:email_security_appliance_7050_firmwaresonicwall:email_security_appliance_8300sonicwall:email_security_appliance_8300_firmwaresonicwall:email_security_appliance_9000sonicwall:email_security_appliance_9000_firmwaresonicwall:email_security_virtual_appliancesonicwall:hosted_email_security

Schwachen (CWE)

CWE-434CWE-434

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.