Multiple Vulnerabilities in SonicWall Secure Mobile Access (SMA) 100 Series Management Interface Could Allow for Remote Code Execution
ID: 71653d74-a425-5560-a2b3-b1d33f3d089a
STIX ID: report--71653d74-a425-5560-a2b3-b1d33f3d089a
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities in SonicWall SMA100 management interface and Apache mod_rewrite (CVE-2023-44221 and CVE-2024-38475) can be combined to allow a remote, authenticated attacker with administrative privileges to perform OS command injection and map URLs to filesystem locations, potentially enabling remote code execution, session hijacking, and full system compromise. The report maps these issues to the Initial Access tactic and Exploit Public-Facing Application technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
