CVE-2021-20022

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_3300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_3300:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_4300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_4300:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_8300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_8300:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*

Configuration 10 (hide)

OR cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:hosted_email_security:*:*:*:*:*:*:*:*

History

10 Nov 2025, 19:07

Type Values Removed Values Added
First Time Sonicwall email Security Appliance 4300 Firmware
Sonicwall email Security Appliance 7000 Firmware
Sonicwall email Security Appliance 3300
Sonicwall email Security Appliance 5050 Firmware
Sonicwall email Security Appliance 7050 Firmware
Sonicwall email Security Appliance 7050
Sonicwall email Security Appliance 5000
Sonicwall email Security Appliance 5000 Firmware
Sonicwall email Security Appliance 8300
Sonicwall email Security Appliance 9000 Firmware
Sonicwall email Security Appliance 3300 Firmware
Sonicwall email Security Appliance 7000
Sonicwall email Security Appliance 5050
Sonicwall email Security Appliance 4300
Sonicwall email Security Virtual Appliance
Sonicwall email Security Appliance 9000
Sonicwall email Security Appliance 8300 Firmware
Microsoft
Microsoft windows
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20022 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20022 - US Government Resource
CPE cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_3300:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_4300:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_8300:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_4300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_3300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_8300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*
CVSS v2 : 6.5
v3 : 7.2
v2 : 7.5
v3 : 7.2

Information

Published : 2021-04-09 18:15

Updated : 2025-11-10 19:07


NVD link : CVE-2021-20022

Mitre link : CVE-2021-20022

CVE.ORG link : CVE-2021-20022


JSON object : View

Products Affected

sonicwall

  • email_security_appliance_9000
  • email_security_appliance_4300
  • email_security_virtual_appliance
  • email_security_appliance_8300
  • email_security_appliance_7050_firmware
  • email_security_appliance_5050
  • email_security_appliance_3300
  • email_security_appliance_7050
  • email_security_appliance_7000
  • email_security_appliance_5050_firmware
  • email_security_appliance_7000_firmware
  • email_security
  • email_security_appliance_9000_firmware
  • email_security_appliance_4300_firmware
  • hosted_email_security
  • email_security_appliance_3300_firmware
  • email_security_appliance_5000_firmware
  • email_security_appliance_8300_firmware
  • email_security_appliance_5000

microsoft

  • windows
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type