← Vulnerability feed

Vulnerability record · CVE-2021-20021 · published 9 April 2021

CVE-2021-20021: SonicWall Email Security improper privilege management allows admin account creation

Sonicwall · Email Security

SonicWall Email Security 10.0.9.x contains an improper privilege management flaw that lets an attacker create an administrative account by sending a crafted HTTP request to the remote host. Because the resulting account is administrative, a successful hit gives full control of the email security appliance, which sits in a sensitive position handling mail flow and credentials.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 89% · top 0.2% CWE-269 · Improper privilege management
9.8CVSS 3.1 base score, v2 7.5
89%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
11Affected product versions listed by NVD
3References
12 Aug 2026Last modified by NVD

Description

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote administrative account creation on an internet-facing email security appliance, with KEV listing, ransomware association and very high EPSS probability.

What it is

SonicWall Email Security 10.0.9.x contains an improper privilege management flaw that lets an attacker create an administrative account by sending a crafted HTTP request to the remote host. Because the resulting account is administrative, a successful hit gives full control of the email security appliance, which sits in a sensitive position handling mail flow and credentials.

Impact

An unauthenticated attacker gains a working administrative account on the appliance, yielding full control over its configuration, mail handling and any data it processes.

Attack surface

Reachable over the network via a crafted HTTP request to the remote host; the CVSS vector shows no privileges and no user interaction required. No further detail on the specific endpoint or request shape is provided in the record.

Exploitation

Listed in CISA KEV with a due date of 2021-11-17 and flagged for known ransomware campaign use, and EPSS gives a 30-day probability of 0.834 (99.7th percentile), indicating active exploitation.

What to do

  • Apply the vendor update per the SonicWall PSIRT advisory SNWLID-2021-0007; treat this as the first and mandatory step.
  • If patching cannot be done immediately, restrict network access to the Email Security management interface to trusted administrative networks only.
  • Audit local accounts on all Email Security appliances and hosted instances for unexpected or newly created administrative users, and remove any that are not authorized.
  • Rotate credentials and review mail-flow and configuration changes made since exposure, since an attacker-created admin account may have been used for follow-on activity.
  • Monitor CISA KEV guidance and vendor advisories for updated remediation instructions.

Detection

  • Review Email Security appliance logs for unexpected administrative account creation events and for HTTP requests to account-management endpoints from untrusted sources.
  • Alert on new or modified admin accounts on Email Security appliances and correlate with source IP reputation and geolocation.
  • Hunt for authentication from newly created admin accounts, especially logins from IPs not previously seen administering the appliance.
  • Monitor for configuration changes, mail rule modifications or data exfiltration consistent with post-exploitation of an email security appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-20021 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall Email Security Improper Privilege Management Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20021 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed7.2CVE-2021-20022SonicWall Email Security post-auth unrestricted file uploadSonicWall Email Security 10.0.9.x allows an authenticated attacker to upload an arbitrary file to the remote host (CWE-434). Because the upload is un…KEVEPSS 17%analysed4.9CVE-2021-20023SonicWall Email Security path traversal allows authenticated file readSonicWall Email Security 10.0.9.x contains a path traversal flaw (CWE-22) that lets an authenticated attacker read arbitrary files on the remote host…KEVEPSS 51%analysed9.8CVE-2025-40604Sonicwall email security appliance 5000 firmware download of code without integrity check vulnerabilityDownload of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signa…EPSS 0.19%7.4CVE-2021-3450Openssl improper certificate validation vulnerabilityThe X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Sta…EPSS 18%5.9CVE-2021-45105Apache Log4j2 uncontrolled recursion in self-referential lookups causes DoSApache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) fail to protect against uncontrolled recursion from self-referential lo…EPSS 100%analysed5.3CVE-2025-40605Sonicwall email security appliance 5000 firmware relative path traversal vulnerabilityA Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting cr…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2021-20021), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.