logo

Credential Access Campaign Targeting SonicWall SMA Devices Potentially Linked to Exploitation of CVE-2021-20035

ID: 8b45e714-4e7c-5775-9ed9-c92904da1741

STIX ID: report--8b45e714-4e7c-5775-9ed9-c92904da1741

Feed Name: Arctic Wolf

Threat Score
70/100

Date Published: 2025-04-17

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

Arctic Wolf reports an ongoing campaign (Jan–Apr 2025) targeting SonicWall SMA 100 series appliances that leverages CVE-2021-20035 — recently reclassified by SonicWall as allowing remote code execution and added to CISA’s KEV — alongside credential access techniques (including exploitation of default local admin credentials) to compromise VPN accounts; mitigation guidance includes upgrading to fixed versions, enforcing MFA, resetting/strengthening local passwords, limiting VPN access, disabling unneeded accounts, and enabling syslog monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.