Zero-day vulnerability in SonicWall On-premise Email Security (ES)

Arbitrary file upload

The vulnerability was used in a chained attack to compromise the affected system.

Vulnerability details

Advisory: SB2021041210 - Multiple vulnerabilities in SonicWall On-premise Email Security (ES) and Hosted Email Security (HES)

Vulnerable component: SonicWall On-premise Email Security (ES)

CVE-ID: CVE-2021-20022

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-434 - Unrestricted Upload of File with Dangerous Type


The vulnerability allows a remote user to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload within the branding feature. A remote administrator can upload a malicious ZIP archive to the system to an arbitrary location using directory traversal sequences in the filenames inside the uploaded archive and compromise the affected system.

Note, the vulnerability is being actively exploited in the wild.