EXPOSURES › CVE-2021-20022
CVE-2021-20022
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSonicWall Email Security allowed authenticated attackers to upload malicious files, exploited in the wild with ransomware connections.
A vulnerability in SonicWall Email Security permitted authenticated users to upload files of any type, enabling privilege escalation when chained with other vulnerabilities and actively exploited by attackers, potentially leading to ransomware deployment. DIB organizations using this product must immediately patch and review access controls to prevent compromise and maintain CMMC compliance.
Shame score — The unrestricted file upload, combined with active exploitation and ransomware links, demonstrates a significant failure in secure coding practices and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation."