
Severity
High
Analysis Summary
CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2021-20022
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
CVE-2021-20020
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
Impact
- Remote code execution
- Privilege access
Affected Vendors
Sonicwall
Affected Products
SonicWall Email Security version 10.0.9.x
Remediation
Users are advised to update to the latest version.