EXPOSURES › CVE-2021-20021
CVE-2021-20021
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSonicWall Email Security allowed attackers to create administrative accounts via a crafted HTTP request, enabling privilege escalation and ransomware attacks.
A vulnerability in SonicWall Email Security allowed unauthorized administrative account creation, frequently exploited in conjunction with other vulnerabilities to escalate privileges and facilitate ransomware deployment; DIB organizations using this product must immediately patch and review access controls.
Shame score — The ease of privilege escalation via a simple HTTP request demonstrates a significant design flaw and lack of basic access controls, contributing to active exploitation and ransomware propagation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
"SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |