PT-2021-2799 · Sonicwall · Sonicwall Hosted Email Security+1
Published
2021-04-09
·
Updated
2025-06-24
·
CVE-2021-20022
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SonicWall Email Security version 10.0.9.x
SonicWall Hosted Email Security (affected versions not specified)
Description
The issue is related to insufficient file checking during upload, allowing a remote attacker to gain unauthorized access to protected information by uploading a malicious ZIP archive. This can impact the confidentiality, integrity, and availability of the protected information. The vulnerability can be exploited by a post-authenticated attacker to upload an arbitrary file to the remote host.
Recommendations
For SonicWall Email Security version 10.0.9.x, consider restricting file uploads until a patch is available.
For SonicWall Hosted Email Security, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonicwall Email Security
Sonicwall Hosted Email Security