Known vulnerabilities in SonicWall Hosted Email Security (HES)
Vendor:
SonicWall
Software:
SonicWall Hosted Email Security (HES)
Software CPE:
cpe:2.3:a:sonicwall:sonicwall_hosted_email_security_hes:*:*:*:*:*:*:*:*
Website:
https://www.sonicwall.com/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU65333 - Improperly Implemented Security Check for Standard CVE-2022-2324 |
CWE-358 | Medium | 10.0.18.7423 | 15.07.2022 |
SB2022071506 |
||
| #VU53230 - Use of Hard-coded Credentials CVE-2021-20025 |
CWE-798 | Medium | 10.0.10 | 13.05.2021 |
SB2021051315 |
||
| #VU52377 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-20023 |
CWE-22 | High | 10.0.9.6173, 10.0.9.6177 | 20.04.2021 |
SB2021042016 |
||
| #VU52039 - Unrestricted Upload of File with Dangerous Type CVE-2021-20022 |
CWE-434 | High | 10.0.9.6103 | 12.04.2021 |
SB2021041210 |
||
| #VU52038 - Improper Authentication CVE-2021-20021 |
CWE-287 | Critical | 10.0.9.6103 | 12.04.2021 |
SB2021041210 |