SonicWall: SMA100 VPN vulnerabilities now exploited in attacks
ID: 1ca05d23-4519-5d4b-8356-d11d9ad67e56
STIX ID: report--1ca05d23-4519-5d4b-8356-d11d9ad67e56
Feed Name: Bleeping Computer
SonicWall warned that two vulnerabilities—CVE-2023-44221 (post-auth OS command injection) and CVE-2024-38475 (critical Apache mod_rewrite output-escaping leading to remote code execution)—are potentially being exploited in the wild against SMA 200/210/400/410/500v devices; patches are available in firmware 10.2.1.14-75sv and later. The vendor also flagged an exploitation technique through CVE-2024-38475 that can enable session hijacking, referenced prior active exploitation of CVE-2021-20035, and advised administrators to review devices for unauthorized logins and apply updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
