Skip to content
COOEY

EXPOSURES › CVE-2021-20022

CVE-2021-20022

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20022 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

SonicWall Email Security allowed authenticated attackers to upload malicious files, exploited in the wild with ransomware connections.

A vulnerability in SonicWall Email Security permitted authenticated users to upload files of any type, enabling privilege escalation when chained with other vulnerabilities and actively exploited by attackers, potentially leading to ransomware deployment. DIB organizations using this product must immediately patch and review access controls to prevent compromise and maintain CMMC compliance.

Shame score — The unrestricted file upload, combined with active exploitation and ransomware links, demonstrates a significant failure in secure coding practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allowed privilege escalation via known exploit chains, indicating severe security failure.
cooey ↗ severe-fallout -0.60
Vulnerability allowed privilege escalation via known exploit chains, indicating severe security failure.
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.