CVE-2021-20021

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_3300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_3300:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_4300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_4300:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_8300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_8300:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*

Configuration 10 (hide)

OR cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:hosted_email_security:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-04-09 18:15

Updated : 2025-11-10 19:04


NVD link : CVE-2021-20021

Mitre link : CVE-2021-20021

CVE.ORG link : CVE-2021-20021


JSON object : View

Products Affected

sonicwall

  • email_security_appliance_5000_firmware
  • hosted_email_security
  • email_security_appliance_9000_firmware
  • email_security_appliance_8300
  • email_security_appliance_8300_firmware
  • email_security_appliance_5050_firmware
  • email_security_appliance_7050
  • email_security_appliance_7000
  • email_security_appliance_5000
  • email_security_appliance_5050
  • email_security_appliance_4300_firmware
  • email_security_appliance_9000
  • email_security_virtual_appliance
  • email_security_appliance_3300_firmware
  • email_security_appliance_4300
  • email_security_appliance_7000_firmware
  • email_security_appliance_3300
  • email_security
  • email_security_appliance_7050_firmware

microsoft

  • windows
CWE
CWE-269

Improper Privilege Management