CVE-2021-20022
Exploited in the wild. In CISA KEV since 2021‑11‑03. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the recordWhat it is
From the CVE record
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
In plain language
Written by AI from the recordCVE-2021-20022 is a file-upload weakness in SonicWall Email Security products that has been used in real ransomware activity, so most small businesses using these systems should act quickly—upgrade to the fixed versions.
CVE-2021-20022 is a post-authentication arbitrary file upload weakness in SonicWall Email Security (including hosted/email security appliances) that has been listed in CISA’s KEV and used in ransomware campaigns; attackers can upload arbitrary files to the remote host after gaining authenticated access.
If you're affected
- Ransomware entry point
- Full server compromise risk
- Service disruption
- Malware drop via uploaded files
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2021-11-03.
US federal agencies must remediate by 2021-11-17.
Known use in ransomware campaigns.
Apply updates per vendor instructions.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
17% chance of exploitation activity in the next 30 days, which ranks it in the 97th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
9 events over 1951 days, from the signal feeds we watch.
- Patch availablerecord updated
- OpenVAS check added
- Patch availablerecord updated
- Added to CISA KEVransomware campaign
- Publishedweakness classified, att&ck mapped
Affected products
- Email SecurityNetworking Infrastructure
- Hosted Email SecurityNetworking Infrastructure
- email security appliance 9000 firmwareNetworking Infrastructure
- email security appliance 3300 firmwareNetworking Infrastructure
- email security appliance 4300 firmwareNetworking Infrastructure
- email security appliance 8300 firmwareNetworking Infrastructure
- email security appliance 5000 firmwareNetworking Infrastructure
- email security appliance 7000 firmwareNetworking Infrastructure
And 5 more affected products. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Scored 7.2 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required HighRequires admin or elevated privileges
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
- Command and ControlT1105Ingress Tool Transferhigh confidence
- Initial AccessT1190Exploit Public-Facing Applicationhigh confidence
- PersistenceT1505Server Software Componenthigh confidence
Sources
References in the record
- nvd.nist.gov/vuln/detail/CVE-2021-20022&
- psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008&
- securitylab.ru/news/519133.php&
And 4 more references. See all after sign-in
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Email Security, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI