Skip to content
COOEY

EXPOSURES › CVE-2021-20023

CVE-2021-20023

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20023 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

SonicWall Email Security allowed authenticated attackers to read files via a path traversal vulnerability, actively exploited in ransomware attacks.

A path traversal vulnerability in SonicWall Email Security enabled attackers to read files, often in conjunction with other vulnerabilities to escalate privileges; DIB organizations using this product face potential data exposure and compliance failures (NIST 800-171 controls 3.1.1, 3.1.2) and should immediately patch or mitigate.

Shame score — The vulnerability's exploitation in a ransomware chain and the ease of file access demonstrate a significant security oversight by SonicWall.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability exploited in known chains for privilege escalation, indicating severe security failure.
cooey ↗ severe-fallout -0.60
Vulnerability exploited in known chains for privilege escalation, indicating severe security failure.
"This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.