CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-20023
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 4.9. EPSS estimates 51.4% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
- State
- PUBLISHED
- Published
- Apr 20, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 98%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAsonicwallOriginal evidence ↗
Record text: SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
Inspect raw assertion
- Field
container- Value
- SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: SonicWall Email Security Path Traversal Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall Email Security Path Traversal Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 51.41% probability · 98.85th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.514070000000; percentile 0.988540000000
FIRST EPSS · score date Aug 26, 2026 · 98.9th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
Inspect raw assertion
- Field
container- Value
- SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
SonicWall Email Security Path Traversal Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- SonicWall Email Security Path Traversal Vulnerability
51.41% probability · 98.85th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.514070000000; percentile 0.988540000000
Applicability
Cited product scope
Grouped from 19 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
21 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.9 and earlier"}]product-6a798dc931affc038ba266631a506d54b455ffebd96b4fae68f77b6bd7aef178Linked exactInspect raw assertion
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2572d17-1de6-457b-99cc-64afd54487ea
product-8032d4f22b7d3397a845ea356098f4c3945c36e2f8540a16b57fa97e7e7d5b16Linked exactInspect raw assertion
cpe:2.3:a:sonicwall:email_security:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6173
- Match ID
5ea2ae41-bcd4-4f77-8883-d201c1afd110
product-fb798830edf27decb7eb7af6d679b1587e116d1bdf82134856f9f73d2894d2efLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_3300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ecf2b5a6-b62f-444e-bdb3-0084896cd83b
product-0210691c540dda8ea8c26bcff7e4480bc0b4e67d742648e1170722a10cf1166fLinked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_3300_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
28af18a3-3e72-400a-81a3-e0d32d550fc1
product-22475d8de9d810465c36cf148d29ff8cd8101dd6837adb295027cd0c427d6e1dLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_4300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a18dccaf-a373-4550-805b-ef329643b068
product-3daebdd08046e268eb38b447f080791690e9ae927f5780a7c4ba6d59d066c319Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_4300_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
738196af-ecbe-4ac2-914e-1dcf74dfd6a9
product-5351b41ab4582884eba81ad2047ba6fc76957920a1d3ef263b5da7fdf76aab93Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ba9126b7-5c64-4692-954c-6ef71261862c
product-102389b6b283fd0208d90c7d3d04c802e951a41ac62a7dabc90cace3ebef8afaLinked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
848ad231-f47d-49e3-b10b-5247240191ea
product-7c18ba97f8280a5899fe4825ce40337ad053d47a4e5ecb048e69608890058f38Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
271f06dd-8daa-46ef-a803-659ea253cc63
product-ef518c6e5047aacd8df08a0b7a8199a490cea3a1cce7e1e8add8f35e9fcbef52Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
ad7a6c11-2167-4294-97e9-c467ee9e1b78
product-495166c69f39eabf03fc0384c215a464e39820ab6f201da0af2175c98d73a39cLinked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a114e829-5fc6-4321-8d28-c63ec09f9099
product-0aa7a6844e35abeb87371d47935c89c4a23cfd40b42bfae20c873d4171ef0c74Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
9908d0f6-1d47-4c2b-b546-3b5614eb827f
product-2abda4b7608668b6a4e0b3cd058af9c5bf4722c2ac3a66359319c40e376aabb9Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
443b635b-6b08-479b-a635-26724b192bf0
product-1e30eb3e1dc9a301073d4e8faecc0d780bc3412e8aab5d13f080ea31c30df658Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
b6220761-ac7e-42bd-a028-cc12ee9b3430
product-fff6b3e813bb5b0c02d79360476860438577bbb47fa67860742b1490fb0860c7Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_8300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dc5803b4-57f1-4f0c-a459-f367f56afe16
product-8bb3d56a60e8d5c8e71e00cd7f73655faca69f4180cfface4ef04998e6587b65Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_8300_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
4667576a-993f-4622-b7ac-ac62dd6efdfa
product-2e6de5b380ecdfb97f06d5d09532ab71e214705ab00cf93af4a574ce51353662Linked exactInspect raw assertion
cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c2434930-79ab-4aa9-aac8-b116f3cd5cc0
product-d37f181127eb39293298193b5e6a68a4fe9ca4e50feb6d9ec9d4f2b912d5e754Linked exactInspect raw assertion
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
0a418bfa-c4e6-4473-9740-794107f86084
product-1bb49863cc80d4f2f70bce9c57e6701ca2d7df67f7c9118096e165ac944407d8Linked exactInspect raw assertion
cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6177
- Match ID
27799885-b16c-4b14-a780-54e7e20b6cb3
product-649fb9dbd22856eb73f7ca2d15024b58a2743ff3a1dc9d3ed8f6aad1a30e87e7Linked exactInspect raw assertion
cpe:2.3:a:sonicwall:hosted_email_security:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 1
- Logic
- OR
- Version bounds
- through excluding 10.0.9.6173
- Match ID
dcfc13f9-2de3-412f-8c8b-847c81811b11
Affected-product evidence
Accepted scope and product mapping
11 canonical links · 1 source-reported links
vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-0210691c540dda8ea8c26bcff7e4480bc0b4e67d742648e1170722a10cf1166f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
43866631-f16b-4ade-adbb-e2b50f4c605dvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-0aa7a6844e35abeb87371d47935c89c4a23cfd40b42bfae20c873d4171ef0c74
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ad39b2cf-177a-4edf-8210-b53854f10bdbvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-102389b6b283fd0208d90c7d3d04c802e951a41ac62a7dabc90cace3ebef8afa
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e7c4a4f2-e50f-4039-af66-1274670c242bvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-1bb49863cc80d4f2f70bce9c57e6701ca2d7df67f7c9118096e165ac944407d8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6d703511-b818-4384-8996-d42a592fd356vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-1e30eb3e1dc9a301073d4e8faecc0d780bc3412e8aab5d13f080ea31c30df658
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7f4dd147-191d-4dfa-b02a-4c12b1014f20vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-3daebdd08046e268eb38b447f080791690e9ae927f5780a7c4ba6d59d066c319
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5a302c19-7793-4dd8-bbb7-87c9d6d14a9avendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-649fb9dbd22856eb73f7ca2d15024b58a2743ff3a1dc9d3ed8f6aad1a30e87e7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
06b380e3-77fe-4fef-8d2c-1b013c88f9c3vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-8032d4f22b7d3397a845ea356098f4c3945c36e2f8540a16b57fa97e7e7d5b16
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
acc75cca-5eb8-4c61-9e98-fd8880b90b66vendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-8bb3d56a60e8d5c8e71e00cd7f73655faca69f4180cfface4ef04998e6587b65
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
895ea529-0433-4ebc-aa1a-8d28f22e81dfvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-d37f181127eb39293298193b5e6a68a4fe9ca4e50feb6d9ec9d4f2b912d5e754
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
75d066ca-0c9a-4a26-9716-3693f66a520bvendor-88ea7b4aa6d07152b297937bc7e73efc70d62904e8122e245a64c5b028d9fab0 · product-ef518c6e5047aacd8df08a0b7a8199a490cea3a1cce7e1e8add8f35e9fcbef52
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a9284934-fb42-46c1-aa2b-e6098d49a09bCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6da21d2d-73c8-491b-87a1-185b4938af08Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NAV:N/AC:L/Au:S/C:P/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N- Validation
- Valid match
- Recomputed
- 4.9
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.