logo

Follow-Up: SonicWall Updates Advisories for Actively Exploited Vulnerabilities

ID: a9a773a9-431a-5629-ae5d-e8113fd04ed6

STIX ID: report--a9a773a9-431a-5629-ae5d-e8113fd04ed6

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2025-04-30

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

Executive summary: Arctic Wolf and SonicWall advisories describe active and potential exploitation of two SonicWall SMA vulnerabilities (CVE-2024-38475 and CVE-2023-44221) in a credential access campaign. CVE-2023-44221 enables OS command injection (requires valid credentials) and may be used for persistence and lateral movement; CISA added the issues to the Known Exploited Vulnerability catalog and public PoC exploit code has been released, increasing attack likelihood. Recommended mitigations include upgrading to fixed versions, enforcing MFA and strong passwords, limiting VPN access, removing unused accounts, and enabling syslog monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.