Vulnerability record · CVE-2021-20023 · published 20 April 2021
CVE-2021-20023: SonicWall Email Security path traversal allows authenticated file read
Sonicwall · Email Security
SonicWall Email Security 10.0.9.x contains a path traversal flaw (CWE-22) that lets an authenticated attacker read arbitrary files on the remote host. The record does not specify which files or whether the traversal is limited to a particular interface, but arbitrary file read on a mail security appliance can expose configuration and credential material.
Description
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with documented ransomware use and very high EPSS, but exploitation requires an already-privileged account, which limits the exposed population.
What it is
SonicWall Email Security 10.0.9.x contains a path traversal flaw (CWE-22) that lets an authenticated attacker read arbitrary files on the remote host. The record does not specify which files or whether the traversal is limited to a particular interface, but arbitrary file read on a mail security appliance can expose configuration and credential material.
Impact
An attacker with valid credentials gains read access to files on the appliance, which can reveal configuration, stored credentials or other sensitive data useful for lateral movement. The CVSS vector rates confidentiality impact as high with no integrity or availability effect.
Attack surface
The vulnerability is network-reachable (AV:N) and requires high privileges (PR:H), meaning an attacker must already hold an administrative or similarly privileged account. No user interaction is required (UI:N).
Exploitation
CVE-2021-20023 is listed in CISA KEV with a known ransomware campaign association and a 30-day EPSS probability of roughly 0.51 (98.9th percentile), indicating active exploitation in the wild. The only references are the vendor advisory and the CISA KEV entry; no public exploit details are provided in the record.
What to do
- Apply the vendor update per SonicWall PSIRT advisory SNWLID-2021-0010 immediately; this is a KEV-listed flaw with a federal remediation deadline of 2021-11-17.
- Restrict management and administrative access to the Email Security appliance to trusted networks and disable or limit remote administrative interfaces where possible.
- Enforce least privilege and strong unique credentials for appliance accounts, and rotate credentials for any account that may have been exposed.
- Audit appliance accounts for unauthorized or stale privileged users and remove them.
- Monitor for indicators of ransomware activity on or around the appliance given the KEV ransomware association.
Detection
- Review Email Security appliance and web/proxy logs for path traversal patterns (for example ../ sequences) in requests to the management interface.
- Alert on unexpected file read activity or access to sensitive paths by authenticated appliance users.
- Correlate privileged account logins to the appliance with subsequent file access or outbound connections.
- Hunt for known ransomware precursor behavior on hosts and networks adjacent to the appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20023 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall Email Security Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0010 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0010 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20023 | US Government Resource |
Track CVE-2021-20023 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20023), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.