« Volver al listado

Sonicwall

Sonicwall Email Security Appliance 5000 Firmware: vulnerabilidades y CVE

Sonicwall Email Security Appliance 5000 Firmware tiene 5 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses2
Críticas2
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-20021Crítica (9.8)89%⚠ Explotación activa9 abr 2021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2021-20022Alta (7.2)17%⚠ Explotación activa9 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
CVE-2021-20023Media (4.9)52%⚠ Explotación activa20 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-40605Media (5.3)0.33%—20 nov 2025
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files…
CVE-2025-40604Crítica (9.8)0.19%—20 nov 2025
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify…
CVE-2021-20023Media (4.9)52%⚠ Explotación activa20 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
CVE-2021-20021Crítica (9.8)89%⚠ Explotación activa9 abr 2021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2021-20022Alta (7.2)17%⚠ Explotación activa9 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1210 Exploitation of Remote Services2
  3. T1005 Data from Local System1
  4. T1078.002 Domain Accounts1
  5. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Sonicwall