Sonicwall
Sonicwall Email Security Appliance 7000 Firmware: vulnerabilidades y CVE
Sonicwall Email Security Appliance 7000 Firmware tiene 5 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 2 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses2
Críticas2
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-20021 | Crítica (9.8) | 89% | ⚠ Explotación activa | 9 abr 2021 | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. |
| CVE-2021-20022 | Alta (7.2) | 17% | ⚠ Explotación activa | 9 abr 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. |
| CVE-2021-20023 | Media (4.9) | 52% | ⚠ Explotación activa | 20 abr 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-40605 | Media (5.3) | 0.33% | — | 20 nov 2025 | A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files… |
| CVE-2025-40604 | Crítica (9.8) | 0.19% | — | 20 nov 2025 | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify… |
| CVE-2021-20023 | Media (4.9) | 52% | ⚠ Explotación activa | 20 abr 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. |
| CVE-2021-20021 | Crítica (9.8) | 89% | ⚠ Explotación activa | 9 abr 2021 | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. |
| CVE-2021-20022 | Alta (7.2) | 17% | ⚠ Explotación activa | 9 abr 2021 | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.