RaqibCTI
CVE

CVE-2021-20023

P1⬤ KNOWN RANSOMWARE USE
SonicWall Email Security Path Traversal Vulnerability
SonicWall · SonicWall Email Security
Date added (CISA)
2021-11-03
Remediation due
2021-11-17
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date

Description

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.

Source: NVD ↗ · CISA KEV Catalog ↗