CVE-2021-20025: High severity sonicwall email security vulnerability
SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance remotely only when the device is freshly installed and not connected to Mysonicwall.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20025?
CVE-2021-20025 has a moderate severity rating due to the exposure of default credentials.
How do I fix CVE-2021-20025?
To fix CVE-2021-20025, change the default username and password immediately after initial setup.
Which versions of SonicWall Email Security Virtual Appliance are affected by CVE-2021-20025?
CVE-2021-20025 affects SonicWall Email Security Virtual Appliance version 10.0.9 and earlier.
Can CVE-2021-20025 be exploited remotely?
Yes, CVE-2021-20025 can be exploited remotely using the default credentials during initial setup.
Is there a need to monitor logs for CVE-2021-20025?
Yes, it is advisable to monitor logs for any unauthorized access attempts following the identification of CVE-2021-20025.