Rewterz
Rewterz Threat Advisory – ICS: Rockwell Automation Connected Components Workbench
May 17, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-27737 – Apache Traffic Server denial of service
May 17, 2021

Rewterz Threat Advisory – CVE-2021-20025 – SonicWall Email Security Virtual Appliance privilege escalation

Severity

High

Analysis Summary

CVE-2021-20025

SonicWall Email Security Virtual Appliance could allow a local attacker to gain elevated privileges on the system, caused by use of a default username and a password at initial setup. An attacker could exploit this vulnerability to log in to the appliance with root privileges.

Impact

Unauthorized Access

Affected Vendors

SonicWall

Affected Products

  • SonicWall E-mail Security 6.1.1
  • SonicWall E-mail Security 7.4.1.7429
  • SonicWall Email Security Appliance 10.0.2
  • SonicWall Email Secuirty 10.0.9

Remediation

Refer to SNWLID-2021-0012 for patch, upgrade or suggested workaround information.

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0012