LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-20023: SonicWall Email Security Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-20023 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email…

CVE-2021-20023 is a path traversal vulnerability in SonicWall Email Security. A post-authenticated attacker can abuse it to read files on the remote host. CISA notes that this flaw has been used in an exploit chain with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation, and that the vulnerability has known ransomware use. Organizations running this product should treat it as a priority for inventory and remediation.

Because the issue requires authentication yet can feed into broader privilege escalation and ransomware activity, defenders need clear visibility into whether Email Security appliances are present, whether they are patched per the vendor, and whether suspicious file-read or post-authentication activity has occurred.

How it works

The weakness is CWE-22 (path traversal). In products of this class, insufficient validation of user-supplied path or file parameters can let an authenticated session escape the intended directory and request arbitrary files on the host. An attacker who already holds valid credentials (or who obtains them through other means) can craft requests that cause the application to return file contents it should not expose.

CISA states that this vulnerability has known usage in a SonicWall Email Security exploit chain together with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. Exact request formats, parameters, and file targets are not detailed here; confirm mechanics and any proof-of-concept details only against the vendor advisory. The practical risk is unauthorized disclosure of configuration, credential, or system files that then enable further compromise of the appliance or the mail environment it protects.

Am I affected? How to find it in your systems

SonicWall Email Security typically runs as a dedicated appliance or virtual appliance in email perimeter or gateway roles—filtering inbound and outbound mail, applying anti-spam and anti-malware policies, and integrating with directory or mail servers. Inventory every instance in DMZ, email security, or related network segments.

If you cannot determine version or configuration from local tools, obtain that detail from the vendor support portal or appliance management UI and compare it to the fixed releases named in the advisory.

How to remediate

Patch first. Apply updates per vendor instructions, as required by CISA. Obtain the specific fixed build or patch package for SonicWall Email Security from the vendor, stage it in a test or maintenance window if required by change control, then deploy to all affected instances and verify the new version is running.

Confirm the exact update package, any prerequisite steps, and post-install verification only against the vendor advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a post-authenticated path-traversal issue on an email security appliance.

These measures lower likelihood and impact but do not replace the vendor patch. Schedule the official update as soon as operationally possible.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, can lead to breaches. If this appliance was unpatched and reachable by authenticated attackers, assume sensitive files or further privilege escalation may have occurred and follow your incident-response process—containment, credential rotation, forensic review of the host and mail flows, and notification obligations as applicable. You can run a free exposure scan of your email to check known breach data and determine whether addresses associated with your domain appear in published breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSonicWall · SonicWall Email Security
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities