Credential Access Campaign Targeting SonicWall SMA Devices Potentially Linked to Exploitation of CVE-2021-20035
ID: bccb2672-8998-5770-b19c-38d23b7ebc15
STIX ID: report--bccb2672-8998-5770-b19c-38d23b7ebc15
Feed Name: Arctic Wolf
**Arctic Wolf reports an active campaign (Jan–Apr 2025) targeting SonicWall SMA 100 series appliances leveraging CVE-2021-20035 (recently updated to indicate RCE, CVSS 7.2) and weak/default local credentials to obtain VPN access and persistence; SonicWall confirmed in-the-wild exploitation and the issue was added to CISA’s KEV catalog. Recommended mitigations include applying vendor fixes, enforcing MFA, resetting and hardening local passwords, disabling unneeded accounts, limiting VPN access, and enabling syslog monitoring for detection.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
