vulnerability
SonicWall Email Security: Static Credential Vulnerability (CVE-2021-20025)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:M/Au:N/C:C/I:C/A:C) | May 13, 2021 | Oct 11, 2021 | Oct 12, 2021 |
Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
May 13, 2021
Added
Oct 11, 2021
Modified
Oct 12, 2021
Description
SonicWall Email Security Virtual Appliance version 10.0.9 and earlier
versions contain a default username and a password that is used at initial
setup. An attacker could exploit this transitional/temporary user account
from the trusted domain to access the Virtual Appliance remotely only when
the device is freshly installed and not connected to Mysonicwall.
Solution
sonicwall-email-security-cve-2021-20025
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.