Improper Authentication in SonicWall On-premise Email Security (ES) and SonicWall Hosted Email Security (HES) - CVE-2021-20021
Published: April 12, 2021 / Updated: April 21, 2021
SonicWall On-premise Email Security (ES)
SonicWall Hosted Email Security (HES)
SonicWall
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests within the "/createou?data=", responsible for administration capabilities, specifically within the feature that allows application administrators to authorize an additional administrator account from a separate Microsoft Active Directory Organization Unit (AD OU). Requests to this form are not verified to require previous authentication to the appliance. A remote non-authenticated attacker can send a specially crafted XML document via HTTP GET or POST method, create a “role.ouadmin” account and authenticate to the application as an administrator.
Note, the vulnerability is being actively exploited in the wild.