SonicWall Email Security Path Traversal Vulnerability
zetlyn/cve-kev vulnerability cve CVE-2021-20023 known 2021-11-03
Properties
| cwes | CWE-22receipt
What the source handed over{
"cveID": "CVE-2021-20023",
"cwes": "CWE-22",
"dateAdded": "2021-11-03",
"dueDate": "2021-11-17",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
"product": "SonicWall Email Security",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
"vendorProject": "SonicWall",
"vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
} |
|---|---|
| due_date | 2021-11-17receipt
What the source handed over{
"cveID": "CVE-2021-20023",
"cwes": "CWE-22",
"dateAdded": "2021-11-03",
"dueDate": "2021-11-17",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
"product": "SonicWall Email Security",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
"vendorProject": "SonicWall",
"vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
} |
| exploited | yesreceipt
What the source handed over{
"cveID": "CVE-2021-20023",
"cwes": "CWE-22",
"dateAdded": "2021-11-03",
"dueDate": "2021-11-17",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
"product": "SonicWall Email Security",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
"vendorProject": "SonicWall",
"vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
} |
| forensic_triage | falsereceipt
What the source handed over{
"cveID": "CVE-2021-20023",
"cwes": "CWE-22",
"dateAdded": "2021-11-03",
"dueDate": "2021-11-17",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
"product": "SonicWall Email Security",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
"vendorProject": "SonicWall",
"vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
} |
| known_ransomware_campaign_use | Knownreceipt
What the source handed over{
"cveID": "CVE-2021-20023",
"cwes": "CWE-22",
"dateAdded": "2021-11-03",
"dueDate": "2021-11-17",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
"product": "SonicWall Email Security",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
"vendorProject": "SonicWall",
"vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
} |
| product | SonicWall Email Securityreceipt
What the source handed over{
"cveID": "CVE-2021-20023",
"cwes": "CWE-22",
"dateAdded": "2021-11-03",
"dueDate": "2021-11-17",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
"product": "SonicWall Email Security",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
"vendorProject": "SonicWall",
"vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
} |
| vendor_project | SonicWallreceipt
What the source handed over{
"cveID": "CVE-2021-20023",
"cwes": "CWE-22",
"dateAdded": "2021-11-03",
"dueDate": "2021-11-17",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
"product": "SonicWall Email Security",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
"vendorProject": "SonicWall",
"vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
} |
Text
SonicWall Email Security Path Traversal Vulnerability
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.
Apply updates per vendor instructions.
https://nvd.nist.gov/vuln/detail/CVE-2021-20023