Follow-Up: SonicWall Updates Advisories for Actively Exploited Vulnerabilities
ID: a9a773a9-431a-5629-ae5d-e8113fd04ed6
STIX ID: report--a9a773a9-431a-5629-ae5d-e8113fd04ed6
Feed Name: Arctic Wolf
Executive summary: Arctic Wolf and SonicWall advisories describe active and potential exploitation of two SonicWall SMA vulnerabilities (CVE-2024-38475 and CVE-2023-44221) in a credential access campaign. CVE-2023-44221 enables OS command injection (requires valid credentials) and may be used for persistence and lateral movement; CISA added the issues to the Known Exploited Vulnerability catalog and public PoC exploit code has been released, increasing attack likelihood. Recommended mitigations include upgrading to fixed versions, enforcing MFA and strong passwords, limiting VPN access, removing unused accounts, and enabling syslog monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
