LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-20022: SonicWall Email Security Unrestricted Upload of File Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-20022 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has…

CVE-2021-20022 is an unrestricted file-upload weakness in SonicWall Email Security. A post-authenticated attacker can upload a file of a dangerous type to the remote host. CISA notes this flaw has been used in an exploit chain with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation, and it has known ransomware use. Organizations running this product should treat it as a priority until they confirm they are patched and not compromised.

Because the product sits in the email path and often holds privileged access to mail flows and related systems, successful abuse can lead to deeper control of the appliance and lateral movement. Confirm all version and fix details against the vendor advisory before acting.

How it works

The weakness is CWE-434: unrestricted upload of a file with a dangerous type. After authentication, an attacker can place a file on the host that the application should not accept or should not store in an executable or otherwise dangerous location. In this class of flaw, the application fails to adequately validate file type, content, or destination, so a crafted upload can introduce attacker-controlled content onto the system.

CISA states the vulnerability allows a post-authenticated attacker to upload a file to the remote host and that it has been used together with CVE-2021-20021 and CVE-2021-20023 in a SonicWall Email Security exploit chain aimed at privilege escalation. Exact upload paths, file-type checks bypassed, or post-upload execution steps are not detailed here; treat any authenticated session that can reach upload functionality as in scope and verify behavior against the vendor advisory. Do not assume unauthenticated access is required—authentication is part of the described attack path.

Am I affected? How to find it in your systems

SonicWall Email Security is typically deployed as an on-premises or virtual appliance that filters, scans, or relays organizational email. Inventory every instance: management consoles, virtual machines, physical appliances, and any high-availability or lab copies. Check asset management, network scans for SonicWall management interfaces, and configuration-management databases for “Email Security” or related SonicWall email products.

Absence of obvious log noise does not prove safety; confirm patch status directly.

How to remediate

Patch first. Apply the updates SonicWall provides for this vulnerability, following the vendor’s instructions exactly (CISA’s required action is to apply updates per vendor instructions). Schedule maintenance windows promptly for internet-facing or high-value instances.

Confirm every step against the current vendor advisory; do not assume a generic “latest” build is sufficient without checking the CVE-specific fix.

If you can't patch immediately

Reduce the attack surface until the vendor update can be applied.

Plan the actual patch deployment; compensating controls only buy time.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to full appliance compromise and follow-on data theft or encryption. If this product was unpatched and reachable by authenticated attackers during the relevant window, assume possible exposure of mail-related data, credentials, or downstream systems until you investigate. Isolate suspect hosts, preserve logs and disk images, hunt for persistence and lateral movement, and follow your incident-response plan. As a simple additional check, you can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or identities have appeared in public breach sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SonicWall Email Security
WeaknessCWE-434
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities