logo

CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation

ID: 7346dfe7-4b83-599a-bf3f-b5647ba812f3

STIX ID: report--7346dfe7-4b83-599a-bf3f-b5647ba812f3

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-05-06

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

CISA has added two SonicWall SMA vulnerabilities (CVE-2023-44221: pre-auth arbitrary file read, CVSS 7.2; and CVE-2024-38475: post-auth OS command injection, CVSS 9.8) to the Known Exploited Vulnerabilities catalog. The flaws affect SMA 200/210/400/410/500v devices, have patches available, and were the subject of technical details published by WatchTowr; SonicWall and CISA warn of potential in-the-wild exploitation and urge immediate review and patching of affected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.