Finding #146 — CVE-2021-20022
| Inventory item | apache-test 2.4.37 (software, apache) |
|---|---|
| Title | SonicWall SonicWall Email Security: SonicWall Email Security Improper Privilege Management Vulnerability |
| Match | keyword / confidence low |
| Status | new |
| First seen | 2026-06-11T07:35:12Z |
| Last updated | 2026-06-11T07:35:12Z |
| CVE | CVE-2021-20022 KEV since 2021-11-03 |
| CVSS | 7.2 (HIGH)CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Description | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. |
| Source advisory | SonicWall SonicWall Email Security: SonicWall Email Security Improper Privilege Management Vulnerability SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. |
| References | https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20022 |