Hosted Email Security
Vendor:
First CVE: Apr 9, 2021 · Active for 5 years
4
Total CVEs
More Total CVEs than 75% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
75.0%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Hosted Email Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2021
5 years ago
Most Recent CVE
Jul 29, 2022
1,459 days ago
CVE Severity & Scoring
Hosted Email Security4 CVEs
25%
50%
25%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High2 (50.0%)
None2 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20021CRITICAL A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | Apr 9, 2021 | 9.8 | 96 | YES | YES |
CVE-2021-20023MEDIUM SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | Apr 20, 2021 | 4.9 | 80 | YES | NO |
CVE-2021-20022HIGH SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | Apr 9, 2021 | 7.2 | 64 | YES | NO |
CVE-2022-2324HIGH Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impa | Jul 29, 2022 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
3 CVEs
75.0% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
25.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CWEs
Versions
No cataloged versions.