QID 730399
Date Published: 2022-03-15
QID 730399: SonicWall On-Premise Email Security Multiple Security Vulnerabilities (SNWLID-2021-0007,SNWLID-2021-0008)
SonicWall Email Security appliances and software provide multi-layered protection from inbound and outbound email threats and compliance violations by scanning all inbound and outbound email content, URLs and attachments for sensitive data, delivering real-time protection against ransomware, targeted phishing, spoofing, viruses, malicious URLs, zombies, directory harvest (DHA), Denial of Service (DoS) and other attacks.
CVE-2021-20021: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2021-20022: SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Affected Versions:
SonicWall On-premise Email Security (ES) 10.0.9 and earlier versions
NOTE:
CVEs are only affected for windows platform.
QID Detection Logic (Unauthenticated):
Look for affected versions by sending a get request to "login.html" endpoint.
Successful exploitation of these vulnerability may allow an remote attacker to create an administrative account by sending a crafted HTTP request to the remote host or with sufficient privileges to create an administrative account by sending a crafted HTTP request to the remote host.
- SNWLID-2021-0007 -
psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0007 - SNWLID-2021-0008 -
psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0008
CVEs related to QID 730399
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SNWLID-2021-0007 |
|
||
| SNWLID-2021-0008 |
|