CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation
ID: 7346dfe7-4b83-599a-bf3f-b5647ba812f3
STIX ID: report--7346dfe7-4b83-599a-bf3f-b5647ba812f3
Feed Name: Dark Reading
Date Published: 2025-05-06
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
CISA has added two SonicWall SMA vulnerabilities (CVE-2023-44221: pre-auth arbitrary file read, CVSS 7.2; and CVE-2024-38475: post-auth OS command injection, CVSS 9.8) to the Known Exploited Vulnerabilities catalog. The flaws affect SMA 200/210/400/410/500v devices, have patches available, and were the subject of technical details published by WatchTowr; SonicWall and CISA warn of potential in-the-wild exploitation and urge immediate review and patching of affected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
