Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-20021


A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.


Published

2021-04-09T18:15:13.380

Last Modified

2025-11-10T19:04:58.607

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-269
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sonicwall email_security < 10.0.9.6103 Yes
Operating System microsoft windows - No
Operating System sonicwall email_security_appliance_9000_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_9000 - No
Operating System sonicwall email_security_appliance_3300_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_3300 - No
Operating System sonicwall email_security_appliance_4300_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_4300 - No
Operating System sonicwall email_security_appliance_8300_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_8300 - No
Operating System sonicwall email_security_appliance_5000_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_5000 - No
Operating System sonicwall email_security_appliance_7000_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_7000 - No
Operating System sonicwall email_security_appliance_5050_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_5050 - No
Operating System sonicwall email_security_appliance_7050_firmware < 10.0.9.6105 Yes
Hardware sonicwall email_security_appliance_7050 - No
Application sonicwall email_security_virtual_appliance < 10.0.9.6105 Yes
Application sonicwall hosted_email_security < 10.0.9.6103 Yes

References