Vulnerability record · CVE-2021-20022 · published 9 April 2021
CVE-2021-20022: SonicWall Email Security post-auth unrestricted file upload
Sonicwall · Email Security
SonicWall Email Security 10.0.9.x allows an authenticated attacker to upload an arbitrary file to the remote host (CWE-434). Because the upload is unrestricted, a file placed on the appliance can be used to execute code or otherwise compromise the host, making this a serious risk for internet-facing email security appliances.
Description
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe vulnerability is in CISA KEV with known ransomware use and a high EPSS percentile, but exploitation requires valid authenticated access, which limits the attacker pool.
What it is
SonicWall Email Security 10.0.9.x allows an authenticated attacker to upload an arbitrary file to the remote host (CWE-434). Because the upload is unrestricted, a file placed on the appliance can be used to execute code or otherwise compromise the host, making this a serious risk for internet-facing email security appliances.
Impact
An attacker with valid credentials gains the ability to write arbitrary files to the appliance, which can lead to code execution and full compromise of the email security host.
Attack surface
The flaw is reachable over the network (AV:N) with low attack complexity, but requires high privileges, meaning the attacker must already hold an authenticated account on the appliance. No user interaction is required.
Exploitation
CVE-2021-20022 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and EPSS shows a 30-day probability of roughly 16.5 percent (96.8th percentile), indicating observed exploitation in the wild.
What to do
- Apply the vendor update referenced in SonicWall advisory SNWLID-2021-0008 as soon as possible.
- Restrict and audit administrative and user accounts on Email Security appliances, removing unused or default accounts.
- Limit network exposure of the appliance management interface to trusted networks only.
- Monitor file system changes and uploaded content on the appliance for unexpected or executable files.
- Review authentication logs for suspicious logins preceding file upload activity.
Detection
- Alert on file creation or modification events in web-accessible or application directories on the Email Security appliance.
- Monitor for uploads of executable or script file types (for example .jsp, .war, .php, .exe) through the appliance web interface.
- Correlate successful authentication events with subsequent file write activity on the host.
- Review appliance and web server logs for anomalous POST requests to upload endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20022 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall Email Security Unrestricted Upload of File Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20022 | US Government Resource |
Track CVE-2021-20022 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20022), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.