Vulnerability Description
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Email Security | < 10.0.9.6173 |
| Microsoft | Windows | - |
| Sonicwall | Email Security Appliance 9000 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 9000 | - |
| Sonicwall | Email Security Appliance 3300 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 3300 | - |
| Sonicwall | Email Security Appliance 4300 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 4300 | - |
| Sonicwall | Email Security Appliance 8300 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 8300 | - |
| Sonicwall | Email Security Appliance 5000 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 5000 | - |
| Sonicwall | Email Security Appliance 7000 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 7000 | - |
| Sonicwall | Email Security Appliance 5050 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 5050 | - |
| Sonicwall | Email Security Appliance 7050 Firmware | < 10.0.9.6177 |
| Sonicwall | Email Security Appliance 7050 | - |
| Sonicwall | Email Security Virtual Appliance | < 10.0.9.6177 |
| Sonicwall | Hosted Email Security | < 10.0.9.6173 |
Related Weaknesses (CWE)
References
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0010Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0010Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-20023?
CVE-2021-20023 is a vulnerability with a CVSS score of 4.9 (MEDIUM). SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
How severe is CVE-2021-20023?
CVE-2021-20023 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20023?
Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Email Security, Microsoft Windows, Sonicwall Email Security Appliance 9000 Firmware, Sonicwall Email Security Appliance 9000, Sonicwall Email Security Appliance 3300 Firmware.