CVE-2021-20023
Last modified
CVE-2021-20023 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.. CISA has confirmed active exploitation in the wild. EPSS estimates a 50.23% chance of exploitation in the next 30 days.
Description
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Email Security | < 10.0.9.6173 |
| Sonicwall | Email Security Appliance 9000 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 3300 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 4300 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 8300 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 5000 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 7000 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 5050 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 7050 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Virtual Appliance | < 10.0.9.6177 |
| Sonicwall | Hosted Email Security | < 10.0.9.6173 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-20023?
How severe is CVE-2021-20023?
How do I fix CVE-2021-20023?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-20018A post-authenticated vulnerability in SonicWall SMA100 allow…4.9
- CVE-2021-20019A vulnerability in SonicOS where the HTTP server response le…7.5
- CVE-2021-2002Vulnerability in the MySQL Server product of Oracle MySQL (c…4.9
- CVE-2021-20020A command execution vulnerability in SonicWall GMS 9.3 allow…9.8
- CVE-2021-20021A vulnerability in the SonicWall Email Security version 10.0…9.8
- CVE-2021-20022SonicWall Email Security version 10.0.9.x contains a vulnera…7.2
- CVE-2021-20024Multiple Out-of-Bound read vulnerability in SonicWall Switch…8.1
- CVE-2021-20025SonicWall Email Security Virtual Appliance version 10.0.9 an…7.8
- CVE-2021-20026A vulnerability in the SonicWall NSM On-Prem product allows …8.8
- CVE-2021-20027A buffer overflow vulnerability in SonicOS allows a remote a…7.5
- CVE-2021-20028Improper neutralization of a SQL Command leading to SQL Inje…9.8
- CVE-2021-2003Vulnerability in the Business Intelligence Enterprise Editio…5.4
Are you affected by CVE-2021-20023?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
