SonicWall Email Security Path Traversal Vulnerability

zetlyn/cve-kev vulnerability cve CVE-2021-20023 known 2021-11-03

Properties

cwesCWE-22
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-22
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
What the source handed over
{
  "cveID": "CVE-2021-20023",
  "cwes": "CWE-22",
  "dateAdded": "2021-11-03",
  "dueDate": "2021-11-17",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
  "product": "SonicWall Email Security",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
  "vendorProject": "SonicWall",
  "vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
}
due_date2021-11-17
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2021-11-17
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
What the source handed over
{
  "cveID": "CVE-2021-20023",
  "cwes": "CWE-22",
  "dateAdded": "2021-11-03",
  "dueDate": "2021-11-17",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
  "product": "SonicWall Email Security",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
  "vendorProject": "SonicWall",
  "vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
}
exploitedyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
What the source handed over
{
  "cveID": "CVE-2021-20023",
  "cwes": "CWE-22",
  "dateAdded": "2021-11-03",
  "dueDate": "2021-11-17",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
  "product": "SonicWall Email Security",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
  "vendorProject": "SonicWall",
  "vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
}
forensic_triagefalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
What the source handed over
{
  "cveID": "CVE-2021-20023",
  "cwes": "CWE-22",
  "dateAdded": "2021-11-03",
  "dueDate": "2021-11-17",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
  "product": "SonicWall Email Security",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
  "vendorProject": "SonicWall",
  "vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
}
known_ransomware_campaign_useKnown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Known
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
What the source handed over
{
  "cveID": "CVE-2021-20023",
  "cwes": "CWE-22",
  "dateAdded": "2021-11-03",
  "dueDate": "2021-11-17",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
  "product": "SonicWall Email Security",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
  "vendorProject": "SonicWall",
  "vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
}
productSonicWall Email Security
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
SonicWall Email Security
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
What the source handed over
{
  "cveID": "CVE-2021-20023",
  "cwes": "CWE-22",
  "dateAdded": "2021-11-03",
  "dueDate": "2021-11-17",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
  "product": "SonicWall Email Security",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
  "vendorProject": "SonicWall",
  "vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
}
vendor_projectSonicWall
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
SonicWall
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-05 21:42 UTC
What the source handed over
{
  "cveID": "CVE-2021-20023",
  "cwes": "CWE-22",
  "dateAdded": "2021-11-03",
  "dueDate": "2021-11-17",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-20023",
  "product": "SonicWall Email Security",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.",
  "vendorProject": "SonicWall",
  "vulnerabilityName": "SonicWall Email Security Path Traversal Vulnerability"
}

Text

SonicWall Email Security Path Traversal Vulnerability SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-20023