URGENT: SonicWall Devices Under Active Attack – Critical Vulnerabilities Being Exploited in the Wild


# SonicWall Alerts Users to Active Exploitation of SMA100 Security Flaws

SonicWall has confirmed that two recently patched vulnerabilities in its SMA100 Secure Mobile Access appliances are being actively exploited in the wild. These security flaws pose significant risks to organizations using the affected devices.

## Vulnerability Details

**CVE-2023-44221 (CVSS: 7.2)**
– Affects the SSL-VPN management interface
– Allows authenticated attackers with admin privileges to inject arbitrary commands
– Could lead to OS Command Injection as a ‘nobody’ user
– Patched in version 10.2.1.10-62sv (December 4, 2023)

**CVE-2024-38475 (CVSS: 9.8)**
– Related to improper output escaping in Apache HTTP Server’s mod_rewrite
– Enables attackers to map URLs to unauthorized file system locations
– Patched in version 10.2.1.14-75sv (December 4, 2024)

## Affected Devices

The vulnerabilities impact all SMA 100 Series devices, including:
– SMA 200
– SMA 210
– SMA 400
– SMA 410
– SMA 500v

## New Exploitation Technique

In an April 29, 2025 advisory update, SonicWall revealed: “During further analysis, SonicWall and trusted security partners identified an additional exploitation technique using CVE-2024-38475, through which unauthorized access to certain files could enable session hijacking.”

The company has urged customers to check their SMA devices for unauthorized logins. Currently, no details are available regarding specific targets, attack methods, or the scope of these exploitations.

This alert follows CISA’s recent addition of another SonicWall SMA 100 Series vulnerability (CVE-2021-20035) to its Known Exploited Vulnerabilities catalog due to active exploitation evidence.

Share This Article