EXPOSURES › CVE-2021-20023
CVE-2021-20023
CRITICAL ⌖ ON CISA KEV · EXPLOITEDSonicWall Email Security allowed authenticated attackers to read files via a path traversal vulnerability, actively exploited in ransomware attacks.
A path traversal vulnerability in SonicWall Email Security enabled attackers to read files, often in conjunction with other vulnerabilities to escalate privileges; DIB organizations using this product face potential data exposure and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2) and should immediately patch or mitigate.
Shame score — The vulnerability's exploitation in a ransomware chain and the ease of file access demonstrate a significant security oversight by SonicWall.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation."