Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20025

Опубликовано: 13 мая 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 6.9
EPSS Низкий

Описание

SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance remotely only when the device is freshly installed and not connected to Mysonicwall.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sonicwall:email_security_virtual_appliance:*:*:*:*:*:*:*:*
Версия до 10.0.9 (включая)

EPSS

Процентиль: 6%
0.00024
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-798
CWE-798

Связанные уязвимости

github
больше 3 лет назад

SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance remotely only when the device is freshly installed and not connected to Mysonicwall.

EPSS

Процентиль: 6%
0.00024
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-798
CWE-798