CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-20021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 9.8. EPSS estimates 83.4% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
- State
- PUBLISHED
- Published
- Apr 9, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAsonicwallOriginal evidence ↗
Record text: A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: SonicWall Email Security Improper Privilege Management Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall Email Security Improper Privilege Management Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 83.43% probability · 99.66th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.834250000000; percentile 0.996590000000
FIRST EPSS · score date Aug 27, 2026 · 99.7th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Inspect raw assertion
- Field
container- Value
- A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
SonicWall Email Security Improper Privilege Management Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall Email Security Improper Privilege Management Vulnerability
83.43% probability · 99.66th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.834250000000; percentile 0.996590000000
Applicability
Cited product scope
Grouped from 19 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
21 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.9 and earlier"}]product-6a798dc931affc038ba266631a506d54b455ffebd96b4fae68f77b6bd7aef178Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2572d17-1de6-457b-99cc-64afd54487ea
product-8032d4f22b7d3397a845ea356098f4c3945c36e2f8540a16b57fa97e7e7d5b16Linked exactInspect raw assertion
cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6103
- Match ID
08ad853a-995f-435d-b2ac-a7a0745d6172
product-fb798830edf27decb7eb7af6d679b1587e116d1bdf82134856f9f73d2894d2efLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_3300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ecf2b5a6-b62f-444e-bdb3-0084896cd83b
product-0210691c540dda8ea8c26bcff7e4480bc0b4e67d742648e1170722a10cf1166fLinked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_3300_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
aa584c94-2321-4bbc-9fcd-d7c13c57f1da
product-22475d8de9d810465c36cf148d29ff8cd8101dd6837adb295027cd0c427d6e1dLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_4300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a18dccaf-a373-4550-805b-ef329643b068
product-3daebdd08046e268eb38b447f080791690e9ae927f5780a7c4ba6d59d066c319Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_4300_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
8c3c3ab8-e169-4dad-ab81-2a7d54eb2cb4
product-5351b41ab4582884eba81ad2047ba6fc76957920a1d3ef263b5da7fdf76aab93Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba9126b7-5c64-4692-954c-6ef71261862c
product-102389b6b283fd0208d90c7d3d04c802e951a41ac62a7dabc90cace3ebef8afaLinked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
53641cb5-cc2e-4c12-9125-64dce99f0838
product-7c18ba97f8280a5899fe4825ce40337ad053d47a4e5ecb048e69608890058f38Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
271f06dd-8daa-46ef-a803-659ea253cc63
product-ef518c6e5047aacd8df08a0b7a8199a490cea3a1cce7e1e8add8f35e9fcbef52Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
4803b3d7-e19f-4ee2-86bc-1dba18a7e5e6
product-495166c69f39eabf03fc0384c215a464e39820ab6f201da0af2175c98d73a39cLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a114e829-5fc6-4321-8d28-c63ec09f9099
product-0aa7a6844e35abeb87371d47935c89c4a23cfd40b42bfae20c873d4171ef0c74Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
113e3915-7ef3-42ca-8429-5310ea631df1
product-2abda4b7608668b6a4e0b3cd058af9c5bf4722c2ac3a66359319c40e376aabb9Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
443b635b-6b08-479b-a635-26724b192bf0
product-1e30eb3e1dc9a301073d4e8faecc0d780bc3412e8aab5d13f080ea31c30df658Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
75d58601-90f8-4501-9fd0-fa1e1e9db546
product-fff6b3e813bb5b0c02d79360476860438577bbb47fa67860742b1490fb0860c7Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_8300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc5803b4-57f1-4f0c-a459-f367f56afe16
product-8bb3d56a60e8d5c8e71e00cd7f73655faca69f4180cfface4ef04998e6587b65Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_8300_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
866762bf-f65b-4c9c-a08e-1f25041576ae
product-2e6de5b380ecdfb97f06d5d09532ab71e214705ab00cf93af4a574ce51353662Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c2434930-79ab-4aa9-aac8-b116f3cd5cc0
product-d37f181127eb39293298193b5e6a68a4fe9ca4e50feb6d9ec9d4f2b912d5e754Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
a06452b5-695f-4cd8-bb72-affb9c4baa2b
product-1bb49863cc80d4f2f70bce9c57e6701ca2d7df67f7c9118096e165ac944407d8Linked exactInspect raw assertion
cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6105
- Match ID
7a32d7d5-3ec7-4f6e-9c24-edcff7ec5e7e
product-649fb9dbd22856eb73f7ca2d15024b58a2743ff3a1dc9d3ed8f6aad1a30e87e7Linked exactInspect raw assertion
cpe:2.3:a:sonicwall:hosted_email_security:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 1
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6103
- Match ID
d1824412-5a4f-4d69-996e-d4b3e813d21c
Affected-product evidence
Accepted scope and product mapping
11 canonical links · 1 source-reported links
vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-0210691c540dda8ea8c26bcff7e4480bc0b4e67d742648e1170722a10cf1166f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
886454c9-b860-4097-9306-7dc51383508fvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-0aa7a6844e35abeb87371d47935c89c4a23cfd40b42bfae20c873d4171ef0c74
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ae90c8ff-b939-41b0-affe-fb6418ee220dvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-102389b6b283fd0208d90c7d3d04c802e951a41ac62a7dabc90cace3ebef8afa
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1982b03d-a241-4817-b7a8-6e0c299d13davendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-1bb49863cc80d4f2f70bce9c57e6701ca2d7df67f7c9118096e165ac944407d8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
98ebca2f-93ee-4f06-a011-8dbec44f4c28vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-1e30eb3e1dc9a301073d4e8faecc0d780bc3412e8aab5d13f080ea31c30df658
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7f80e153-c829-491f-bdcc-95af4eff5684vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-3daebdd08046e268eb38b447f080791690e9ae927f5780a7c4ba6d59d066c319
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b160a688-d6be-4c24-827a-13ea60bcefb7vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-649fb9dbd22856eb73f7ca2d15024b58a2743ff3a1dc9d3ed8f6aad1a30e87e7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d096d8d3-1a2f-461e-b077-3edc81a6b928vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-8032d4f22b7d3397a845ea356098f4c3945c36e2f8540a16b57fa97e7e7d5b16
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5e767784-a091-4889-9ae4-c33966222436vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-8bb3d56a60e8d5c8e71e00cd7f73655faca69f4180cfface4ef04998e6587b65
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
98930c45-ac93-4679-81da-384da377d398vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-d37f181127eb39293298193b5e6a68a4fe9ca4e50feb6d9ec9d4f2b912d5e754
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6f1d58e5-386c-460b-baa7-59fdb6e79a28vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-ef518c6e5047aacd8df08a0b7a8199a490cea3a1cce7e1e8add8f35e9fcbef52
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3fd1d8b5-3548-4794-9501-8dd5c281792eCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
847dc68e-3215-4f63-b0df-db99577eeee6Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.