Web1 vuln-feed

Finding #146 — CVE-2021-20022

Inventory item apache-test 2.4.37 (software, apache)
TitleSonicWall SonicWall Email Security: SonicWall Email Security Improper Privilege Management Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:12Z
Last updated2026-06-11T07:35:12Z
CVECVE-2021-20022 KEV since 2021-11-03
CVSS7.2 (HIGH)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
DescriptionSonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Source advisorySonicWall SonicWall Email Security: SonicWall Email Security Improper Privilege Management Vulnerability
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
Referenceshttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20022

Update status