CVE-2021-20021SonicWall Email Security Improper Privilege Management Vulnerability

PUBLISHEDvulnerability record
2021-11-03 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2021-20021
项目:
SonicWall
产品:
SonicWall Email Security
添加日期:
2021-11-03
到期日:
2021-11-17
最后更新:
June 21, 2025

漏洞名称

SonicWall Email Security Improper Privilege Management Vulnerability

描述

SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.

已知用于勒索软件活动吗?

勒索软件状态:
KNOWN

采集行动

Apply updates per vendor instructions.

其他说明

相关 CWE