Skip to content
COOEY

EXPOSURES › CVE-2021-20021

CVE-2021-20021

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20021 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

SonicWall Email Security allowed attackers to create administrative accounts via a crafted HTTP request, enabling privilege escalation and ransomware attacks.

A vulnerability in SonicWall Email Security allowed unauthorized administrative account creation, frequently exploited in conjunction with other vulnerabilities to escalate privileges and facilitate ransomware deployment; DIB organizations using this product must immediately patch and review access controls.

Shame score — The ease of privilege escalation via a simple HTTP request demonstrates a significant design flaw and lack of basic access controls, contributing to active exploitation and ransomware propagation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows attacker to create admin account via crafted HTTP request, part of known exploit chain for privilege escalation.
cooey ↗ severe-fallout -0.60
Vulnerability allows attacker to create admin account via crafted HTTP request, part of known exploit chain for privilege escalation.
"SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation."
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized