← Vulnerability feed

Vulnerability record · CVE-2021-20022 · published 9 April 2021

CVE-2021-20022: SonicWall Email Security post-auth unrestricted file upload

Sonicwall · Email Security

SonicWall Email Security 10.0.9.x allows an authenticated attacker to upload an arbitrary file to the remote host (CWE-434). Because the upload is unrestricted, a file placed on the appliance can be used to execute code or otherwise compromise the host, making this a serious risk for internet-facing email security appliances.

7.2 CVSS 3.1 High CISA KEV since 3 Nov 2021 Known ransomware use EPSS 17% · top 3.1% CWE-434 · Unrestricted file upload
7.2CVSS 3.1 base score, v2 7.5
17%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
11Affected product versions listed by NVD
3References
12 Aug 2026Last modified by NVD

Description

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe vulnerability is in CISA KEV with known ransomware use and a high EPSS percentile, but exploitation requires valid authenticated access, which limits the attacker pool.

What it is

SonicWall Email Security 10.0.9.x allows an authenticated attacker to upload an arbitrary file to the remote host (CWE-434). Because the upload is unrestricted, a file placed on the appliance can be used to execute code or otherwise compromise the host, making this a serious risk for internet-facing email security appliances.

Impact

An attacker with valid credentials gains the ability to write arbitrary files to the appliance, which can lead to code execution and full compromise of the email security host.

Attack surface

The flaw is reachable over the network (AV:N) with low attack complexity, but requires high privileges, meaning the attacker must already hold an authenticated account on the appliance. No user interaction is required.

Exploitation

CVE-2021-20022 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and EPSS shows a 30-day probability of roughly 16.5 percent (96.8th percentile), indicating observed exploitation in the wild.

What to do

  • Apply the vendor update referenced in SonicWall advisory SNWLID-2021-0008 as soon as possible.
  • Restrict and audit administrative and user accounts on Email Security appliances, removing unused or default accounts.
  • Limit network exposure of the appliance management interface to trusted networks only.
  • Monitor file system changes and uploaded content on the appliance for unexpected or executable files.
  • Review authentication logs for suspicious logins preceding file upload activity.

Detection

  • Alert on file creation or modification events in web-accessible or application directories on the Email Security appliance.
  • Monitor for uploads of executable or script file types (for example .jsp, .war, .php, .exe) through the appliance web interface.
  • Correlate successful authentication events with subsequent file write activity on the host.
  • Review appliance and web server logs for anomalous POST requests to upload endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-20022 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall Email Security Unrestricted Upload of File Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20022 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2021-20021SonicWall Email Security improper privilege management allows admin account creationSonicWall Email Security 10.0.9.x contains an improper privilege management flaw that lets an attacker create an administrative account by sending a …KEVEPSS 89%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed4.9CVE-2021-20023SonicWall Email Security path traversal allows authenticated file readSonicWall Email Security 10.0.9.x contains a path traversal flaw (CWE-22) that lets an authenticated attacker read arbitrary files on the remote host…KEVEPSS 51%analysed9.8CVE-2025-40604Sonicwall email security appliance 5000 firmware download of code without integrity check vulnerabilityDownload of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signa…EPSS 0.19%7.4CVE-2021-3450Openssl improper certificate validation vulnerabilityThe X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Sta…EPSS 18%5.9CVE-2021-45105Apache Log4j2 uncontrolled recursion in self-referential lookups causes DoSApache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) fail to protect against uncontrolled recursion from self-referential lo…EPSS 100%analysed5.3CVE-2025-40605Sonicwall email security appliance 5000 firmware relative path traversal vulnerabilityA Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting cr…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2021-20022), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.