SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions...
Vulnerability Description
SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password that is used at initial setup. An attacker could exploit this transitional/temporary user account from the trusted domain to access the Virtual Appliance remotely only when the device is freshly installed and not connected to Mysonicwall.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-20025
Credits & Attribution
No credits recorded in the NVD database.
More from SonicWall
View All →Affected Vendor
SonicWall
View all reports →