VendorsSonicWallemail_security_appliance_5000any version
Vulnerabilities

SonicWall Email Security Appliance 5000 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Published 2021-04-09 · Analyzed
9.8KEVEPSS 0.887
CVE-2025-40604
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Published 2025-11-20 · Analyzed
9.8EPSS 0.002
CVE-2021-20022
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Published 2021-04-09 · Analyzed
7.5KEVEPSS 0.165
CVE-2025-40605
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.
Published 2025-11-20 · Analyzed
5.3EPSS 0.003
CVE-2021-20023
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
Published 2021-04-20 · Analyzed
4.9KEVEPSS 0.514