CVE-2021-20021

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_3300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_3300:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_4300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_4300:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_8300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_8300:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*

Configuration 10 (hide)

OR cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:a:sonicwall:hosted_email_security:*:*:*:*:*:*:*:*

History

10 Nov 2025, 19:04

Type Values Removed Values Added
First Time Sonicwall email Security Virtual Appliance
Sonicwall email Security Appliance 7000 Firmware
Sonicwall email Security Appliance 7050
Sonicwall email Security Appliance 5000
Sonicwall email Security Appliance 5050
Sonicwall email Security Appliance 7000
Sonicwall email Security Appliance 3300 Firmware
Sonicwall email Security Appliance 7050 Firmware
Sonicwall email Security Appliance 5050 Firmware
Microsoft
Sonicwall email Security Appliance 9000 Firmware
Sonicwall email Security Appliance 4300 Firmware
Sonicwall email Security Appliance 8300
Sonicwall email Security Appliance 9000
Sonicwall email Security Appliance 5000 Firmware
Microsoft windows
Sonicwall email Security Appliance 4300
Sonicwall email Security Appliance 3300
Sonicwall email Security Appliance 8300 Firmware
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20021 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20021 - US Government Resource
CPE cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_8300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_4300:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_4300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_3300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_8300:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_3300:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*

22 Oct 2025, 00:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20021 -

21 Oct 2025, 20:18

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20021', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:18

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20021 -

21 Nov 2024, 05:45

Type Values Removed Values Added
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0007 - Vendor Advisory () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0007 - Vendor Advisory

Information

Published : 2021-04-09 18:15

Updated : 2025-11-10 19:04


NVD link : CVE-2021-20021

Mitre link : CVE-2021-20021

CVE.ORG link : CVE-2021-20021


JSON object : View

Products Affected

sonicwall

  • email_security_appliance_8300
  • email_security_appliance_5000_firmware
  • email_security_appliance_4300
  • email_security_appliance_5000
  • email_security_appliance_7000
  • email_security_virtual_appliance
  • email_security_appliance_8300_firmware
  • hosted_email_security
  • email_security_appliance_5050_firmware
  • email_security_appliance_3300
  • email_security_appliance_9000_firmware
  • email_security_appliance_7000_firmware
  • email_security_appliance_5050
  • email_security_appliance_4300_firmware
  • email_security
  • email_security_appliance_7050
  • email_security_appliance_3300_firmware
  • email_security_appliance_7050_firmware
  • email_security_appliance_9000

microsoft

  • windows
CWE
CWE-269

Improper Privilege Management