SonicWall Patches Three Zero-Day Vulnerabilities

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines
Posted on April 21, 2021
SonicWall

Written by Raxis Research Team

SonicWall has tested and published patches to mitigate three zero-day vulnerabilities in its email security products this week. Hackers are actively exploiting these vulnerabilities in the wild, and customers should patch them immediately.

Affected Products

The vulnerabilities affected the following versions of SonicWall’s email security and hosted email security products:

  • 10.0.1
  • 10.0.2
  • 10.0.3
  • 10.0.4-Present
The Addressed Vulnerabilities

The patches released by SonicWall mitigate three CVEs, listed below:

More details from SonicWall can be found in its company advisory as well as in FireEye’s detail of how the exploits were being used. Here are links to both:

Remediations

SonicWall has patched its hosted email security product automatically, but customers will need to upgrade in-house email security products on their own, using the following versions:

  • (Windows) Email Security 10.0.9.6173
  • (Hardware & ESXi Virtual Appliance) Email Security 10.0.9.6173

SonicWall also provides detailed instructions for upgrading in this advisory article: https://www.sonicwall.com/support/product-notification/security-notice-sonicwall-email-security-zero-day-vulnerabilities/210416112932360/

 

Raxis Research Team

Raxis Research Team

The Raxis Research Team is dedicated to staying ahead of the threat landscape. Our experts dig into emerging exploits, uncover hidden vulnerabilities, and develop resources that power our penetration testing engagements. By combining curiosity with technical precision, the team equips Raxis testers with cutting-edge intelligence to simulate real-world attacks and strengthen client defenses.

Search The Exploit Blog

Stay up to date with the latest in penetration testing

Name(Required)
Newsletter(Required)
Do you wish to join our newsletter? We send out emails once a month that cover the latest in cybersecurity news. We do not sell your information to other parties.