S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 26, 2025

CVE-2021-20021 Scanner

CVE-2021-20021 Scanner - Unauthenticated Admin Account Creation vulnerability in SonicWall Email Security

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-20021
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Email Securityby SonicWall
10.0.9 and earlier
Updated Aug 21, 2026View on NVD →
Detail

SonicWall Email Security is a comprehensive solution designed for businesses to protect email infrastructures from a variety of threats including phishing and spam attacks. Utilized by enterprises to ensure a safe and spam-free email environment, it offers features like real-time threat intelligence and advanced management capabilities. The software is essential for maintaining email integrity and confidentiality while also being highly scalable to accommodate growing business needs. Enterprises often deploy SonicWall Email Security to safeguard sensitive communications and ensure compliance with industry standards. It's known for its robust security features which help organizations mitigate risk and enhance productivity through efficient email management. Being a critical component of enterprise security strategies, it is widely recognized for its effectiveness in threat prevention.

The vulnerability identified in SonicWall Email Security pertains to the creation of an unauthenticated admin account, which poses a serious security risk. It allows attackers to manipulate the system and gain elevated privileges without proper authorization processes. This form of vulnerability can undermine the security posture of organizations using this software, making it a critical issue. Effective exploitation of this vulnerability can result in unauthorized access to sensitive email data. It primarily affects versions 10.0.9.x and earlier, urging organizations to apply necessary patches swiftly. The severity of this vulnerability calls for immediate attention due to its potential impact on organizational operations.

The vulnerability specifically lies in the handling of requests on the login page of SonicWall Email Security, which is vulnerable to unauthorized access. As defined in its technical aspect, this involves sending a crafted HTTP GET request that does not sufficiently verify credentials, allowing attackers the ability to create administrative accounts. Using this vulnerability, attackers can exploit an endpoint that is configured incorrectly while bypassing standard authentication checks. This bypasses security protocols set in place thereby compromising system integrity. The parameters targeted are not adequately safeguarded, leading to security loopholes. This is a prime example of improper access control that fails to restrict elevated permission allocation.

If this vulnerability is exploited, it may lead to unauthorized access to the system, which could compromise sensitive information managed by SonicWall Email Security. Attackers can take control of the software, manipulate the email security settings, or exfiltrate critical data. The presence of unauthorized administrative accounts can severely compromise the security of email communications. It may also lead to further malware exploitation or significant operational disruption. Additionally, trust in the organization's email communication system could be eroded, leaving it vulnerable to future attacks.

REFERENCES

Solution Advice
  • Immediately update any vulnerable SonicWall Email Security systems to the latest version that addresses this vulnerability.
  • Implement robust access controls to ensure administrative accounts require strong, two-factor authentication.
  • Regularly audit all user accounts to ensure no unauthorized accounts have been created.
  • Enable logging and monitoring of account creation and access activities for early detection of unauthorized access.
  • Consult SonicWall's official security advisories for additional mitigation steps and recommendations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.