Vulnerability record · CVE-2021-20021 · published 9 April 2021
CVE-2021-20021: SonicWall Email Security improper privilege management allows admin account creation
Sonicwall · Email Security
SonicWall Email Security 10.0.9.x contains an improper privilege management flaw that lets an attacker create an administrative account by sending a crafted HTTP request to the remote host. Because the resulting account is administrative, a successful hit gives full control of the email security appliance, which sits in a sensitive position handling mail flow and credentials.
Description
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote administrative account creation on an internet-facing email security appliance, with KEV listing, ransomware association and very high EPSS probability.
What it is
SonicWall Email Security 10.0.9.x contains an improper privilege management flaw that lets an attacker create an administrative account by sending a crafted HTTP request to the remote host. Because the resulting account is administrative, a successful hit gives full control of the email security appliance, which sits in a sensitive position handling mail flow and credentials.
Impact
An unauthenticated attacker gains a working administrative account on the appliance, yielding full control over its configuration, mail handling and any data it processes.
Attack surface
Reachable over the network via a crafted HTTP request to the remote host; the CVSS vector shows no privileges and no user interaction required. No further detail on the specific endpoint or request shape is provided in the record.
Exploitation
Listed in CISA KEV with a due date of 2021-11-17 and flagged for known ransomware campaign use, and EPSS gives a 30-day probability of 0.834 (99.7th percentile), indicating active exploitation.
What to do
- Apply the vendor update per the SonicWall PSIRT advisory SNWLID-2021-0007; treat this as the first and mandatory step.
- If patching cannot be done immediately, restrict network access to the Email Security management interface to trusted administrative networks only.
- Audit local accounts on all Email Security appliances and hosted instances for unexpected or newly created administrative users, and remove any that are not authorized.
- Rotate credentials and review mail-flow and configuration changes made since exposure, since an attacker-created admin account may have been used for follow-on activity.
- Monitor CISA KEV guidance and vendor advisories for updated remediation instructions.
Detection
- Review Email Security appliance logs for unexpected administrative account creation events and for HTTP requests to account-management endpoints from untrusted sources.
- Alert on new or modified admin accounts on Email Security appliances and correlate with source IP reputation and geolocation.
- Hunt for authentication from newly created admin accounts, especially logins from IPs not previously seen administering the appliance.
- Monitor for configuration changes, mail rule modifications or data exfiltration consistent with post-exploitation of an email security appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20021 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall Email Security Improper Privilege Management Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0007 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0007 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20021 | US Government Resource |
Track CVE-2021-20021 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20021), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.