#VU53230 Use of hard-coded credentials in SonicWall On-premise Email Security (ES) and SonicWall Hosted Email Security (HES) - CVE-2021-20025
Published: May 13, 2021
SonicWall On-premise Email Security (ES)
SonicWall Hosted Email Security (HES)
SonicWall
Description
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application code, a default username and a password are used at initial setup. A remote unauthenticated attacker can access the Virtual Appliance using the default credentials only when the device is freshly installed and not connected to Mysonicwall.