Email Security Virtual Appliance
Vendor:
First CVE: Apr 9, 2021 · Active for 5 years
4
Total CVEs
More Total CVEs than 75% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
75.0%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Email Security Virtual Appliance over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2021
5 years ago
Most Recent CVE
May 13, 2021
1,902 days ago
CVE Severity & Scoring
Email Security Virtual Appliance4 CVEs
25%
50%
25%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (25.0%)
Network3 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (25.0%)
High2 (50.0%)
None1 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20021CRITICAL A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | Apr 9, 2021 | 9.8 | 96 | YES | YES |
CVE-2021-20023MEDIUM SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | Apr 20, 2021 | 4.9 | 80 | YES | NO |
CVE-2021-20022HIGH SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | Apr 9, 2021 | 7.2 | 64 | YES | NO |
CVE-2021-20025HIGH SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit th | May 13, 2021 | 7.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
3 CVEs
75.0% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
25.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CWEs
Versions
No cataloged versions.