← Vulnerability feed

Vulnerability record · CVE-2021-20023 · published 20 April 2021

CVE-2021-20023: SonicWall Email Security path traversal allows authenticated file read

Sonicwall · Email Security

SonicWall Email Security 10.0.9.x contains a path traversal flaw (CWE-22) that lets an authenticated attacker read arbitrary files on the remote host. The record does not specify which files or whether the traversal is limited to a particular interface, but arbitrary file read on a mail security appliance can expose configuration and credential material.

4.9 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 Known ransomware use EPSS 51% · top 1.1% CWE-22 · Path traversal
4.9CVSS 3.1 base score, v2 4.0
51%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
11Affected product versions listed by NVD
3References
12 Aug 2026Last modified by NVD

Description

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw is in CISA KEV with documented ransomware use and very high EPSS, but exploitation requires an already-privileged account, which limits the exposed population.

What it is

SonicWall Email Security 10.0.9.x contains a path traversal flaw (CWE-22) that lets an authenticated attacker read arbitrary files on the remote host. The record does not specify which files or whether the traversal is limited to a particular interface, but arbitrary file read on a mail security appliance can expose configuration and credential material.

Impact

An attacker with valid credentials gains read access to files on the appliance, which can reveal configuration, stored credentials or other sensitive data useful for lateral movement. The CVSS vector rates confidentiality impact as high with no integrity or availability effect.

Attack surface

The vulnerability is network-reachable (AV:N) and requires high privileges (PR:H), meaning an attacker must already hold an administrative or similarly privileged account. No user interaction is required (UI:N).

Exploitation

CVE-2021-20023 is listed in CISA KEV with a known ransomware campaign association and a 30-day EPSS probability of roughly 0.51 (98.9th percentile), indicating active exploitation in the wild. The only references are the vendor advisory and the CISA KEV entry; no public exploit details are provided in the record.

What to do

  • Apply the vendor update per SonicWall PSIRT advisory SNWLID-2021-0010 immediately; this is a KEV-listed flaw with a federal remediation deadline of 2021-11-17.
  • Restrict management and administrative access to the Email Security appliance to trusted networks and disable or limit remote administrative interfaces where possible.
  • Enforce least privilege and strong unique credentials for appliance accounts, and rotate credentials for any account that may have been exposed.
  • Audit appliance accounts for unauthorized or stale privileged users and remove them.
  • Monitor for indicators of ransomware activity on or around the appliance given the KEV ransomware association.

Detection

  • Review Email Security appliance and web/proxy logs for path traversal patterns (for example ../ sequences) in requests to the management interface.
  • Alert on unexpected file read activity or access to sensitive paths by authenticated appliance users.
  • Correlate privileged account logins to the appliance with subsequent file access or outbound connections.
  • Hunt for known ransomware precursor behavior on hosts and networks adjacent to the appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-20023 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SonicWall Email Security Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20023 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2021-20021SonicWall Email Security improper privilege management allows admin account creationSonicWall Email Security 10.0.9.x contains an improper privilege management flaw that lets an attacker create an administrative account by sending a …KEVEPSS 89%analysed9.0CVE-2021-45046Apache Log4j 2.15.0 Incomplete Fix Allows JNDI Lookup InjectionThe fix for CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. When a non-default Pattern Layout uses a Cont…KEVEPSS 100%analysed7.2CVE-2021-20022SonicWall Email Security post-auth unrestricted file uploadSonicWall Email Security 10.0.9.x allows an authenticated attacker to upload an arbitrary file to the remote host (CWE-434). Because the upload is un…KEVEPSS 17%analysed9.8CVE-2025-40604Sonicwall email security appliance 5000 firmware download of code without integrity check vulnerabilityDownload of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signa…EPSS 0.19%7.4CVE-2021-3450Openssl improper certificate validation vulnerabilityThe X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Sta…EPSS 18%5.9CVE-2021-45105Apache Log4j2 uncontrolled recursion in self-referential lookups causes DoSApache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) fail to protect against uncontrolled recursion from self-referential lo…EPSS 100%analysed5.3CVE-2025-40605Sonicwall email security appliance 5000 firmware relative path traversal vulnerabilityA Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting cr…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2021-20023), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.