PT-2021-2799 · Sonicwall · Sonicwall Hosted Email Security+1

Published

2021-04-09

·

Updated

2025-06-24

·

CVE-2021-20022

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SonicWall Email Security version 10.0.9.x SonicWall Hosted Email Security (affected versions not specified)
Description The issue is related to insufficient file checking during upload, allowing a remote attacker to gain unauthorized access to protected information by uploading a malicious ZIP archive. This can impact the confidentiality, integrity, and availability of the protected information. The vulnerability can be exploited by a post-authenticated attacker to upload an arbitrary file to the remote host.
Recommendations For SonicWall Email Security version 10.0.9.x, consider restricting file uploads until a patch is available. For SonicWall Hosted Email Security, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02344
BDU:2021-06040
CVE-2021-20022

Affected Products

Sonicwall Email Security
Sonicwall Hosted Email Security