« Volver al listado

Sonicwall

Sonicwall Hosted Email Security: vulnerabilidades y CVE

Sonicwall Hosted Email Security tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses0
Críticas1
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-20021Crítica (9.8)89%⚠ Explotación activa9 abr 2021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2021-20022Alta (7.2)17%⚠ Explotación activa9 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
CVE-2021-20023Media (4.9)51%⚠ Explotación activa20 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-2324Alta (7.5)0.62%—29 jul 2022
Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions
CVE-2021-20023Media (4.9)51%⚠ Explotación activa20 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
CVE-2021-20021Crítica (9.8)89%⚠ Explotación activa9 abr 2021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
CVE-2021-20022Alta (7.2)17%⚠ Explotación activa9 abr 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services2
  2. T1005 Data from Local System1
  3. T1078.002 Domain Accounts1
  4. T1190 Exploit Public-Facing Application1
  5. T1505.003 Web Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Sonicwall