Credential Access Campaign Targeting SonicWall SMA Devices Potentially Linked to Exploitation of CVE-2021-20035
ID: 8b45e714-4e7c-5775-9ed9-c92904da1741
STIX ID: report--8b45e714-4e7c-5775-9ed9-c92904da1741
Feed Name: Arctic Wolf
Arctic Wolf reports an ongoing campaign (Jan–Apr 2025) targeting SonicWall SMA 100 series appliances that leverages CVE-2021-20035 — recently reclassified by SonicWall as allowing remote code execution and added to CISA’s KEV — alongside credential access techniques (including exploitation of default local admin credentials) to compromise VPN accounts; mitigation guidance includes upgrading to fixed versions, enforcing MFA, resetting/strengthening local passwords, limiting VPN access, disabling unneeded accounts, and enabling syslog monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
