Saturday , May 24 2025
SonicWall

Patch Now! SonicWall Confirms Active Exploitation of SMA 100 Vulns

On April 29, 2025, SonicWall announced that two previously disclosed vulnerabilities in its SMA 100 Series appliances are being actively exploited. They urge customers to update to the latest secure firmware to avoid compromise.

First identified in December 2023, CVE-2023-44221 has now been confirmed as under active exploitation. The vulnerability—assigned a CVSS score of 7.2—arises from “improper neutralization of special elements in the SMA100 SSL-VPN management interface,” according to SonicWall’s PSIRT advisory.

Exploitable Vulns in Canon Printers Allow Gaining Admin Privileges

A passback vulnerability has been found in some Canon printers, including production and multifunction models. If an attacker gains administrative...
Read More
Exploitable Vulns in Canon Printers Allow Gaining Admin Privileges

184 Million Leaked Credentials Discovered in Open Database

Security researchers have discovered a database with 184 million account credentials, highlighting the need to update compromised passwords, strengthen weak...
Read More
184 Million Leaked Credentials Discovered in Open Database

Palo Alto Networks Warns of XSS Flaw: PoC Released

Palo Alto Networks warns a reflected cross-site scripting (XSS) vulnerability, CVE-2025-0133, in the GlobalProtect gateway and portal features of its...
Read More
Palo Alto Networks Warns of XSS Flaw: PoC Released

Pwn2Own Berlin reveals 29 critical vulns in major tech firms

Pwn2Own Berlin 2025, a top cybersecurity contest, awarded $1,078,750 to researchers who discovered 29 zero-day vulnerabilities in various enterprise technologies....
Read More
Pwn2Own Berlin reveals 29 critical vulns in major tech firms

High-Severity Flaw Hits Atlassian Jira Data Center

A recently discovered vulnerability, CVE-2025-22157, threatens organizations using Atlassian’s Jira Core Data Center and Jira Service Management Data Center by...
Read More
High-Severity Flaw Hits Atlassian Jira Data Center

All major mobile networks go down across Spain

A nationwide phone network has gone down in Spain, shortly after blackouts caused chaos and significant financial losses. Emergency services...
Read More
All major mobile networks go down across Spain

Researchers found 200 billion files exposed in cloud buckets

Billions of files, including documents, source code, and backups, are leaking because of misconfigured cloud storage. Cyble, a cybersecurity company...
Read More
Researchers found 200 billion files exposed in cloud buckets

Bank server compromised using customer’s mobile, steal ₹11 crore

Cyber fraudsters hacked the Himachal Pradesh State Cooperative Bank's server using a customer's mobile phone. According to reports, the fraudsters...
Read More
Bank server compromised using customer’s mobile, steal ₹11 crore

“InfoSecCon-2025″ held successfully promising cyber resilience

"InfoSecCon-2025" was successfully held with tremendous audiences with various time demanding topics and keynotes at Dhaka on 16 May- 2025....
Read More
“InfoSecCon-2025″ held successfully promising cyber resilience

Intel PC, laptop and server processors affected for 6 years: Report

A new class of vulnerabilities in Intel processors, called Branch Predictor Race Conditions (BPRC), enables attackers to extract sensitive data...
Read More
Intel PC, laptop and server processors affected for 6 years: Report

This flaw lets a remote attacker with admin rights inject OS commands as the ‘nobody’ user. If exploited, it can result in full OS command execution, compromising system confidentiality and integrity.

“During further analysis, SonicWall and trusted security partners identified that CVE-2023-44221 is potentially being exploited in the wild,” the company confirmed. “SMA100 devices updated with the fixed firmware version 10.2.1.10-62sv or latest release version are not vulnerable to CVE-2023-44221 exploitation.”

Impacted Versions:

SMA 100 Series (Models: 200, 210, 400, 410, 500v) running firmware 10.2.1.9-57sv and earlier

Fixed Version:

Firmware 10.2.1.10-62sv and above

A second critical vulnerability, CVE-2024-38475 (CVSS 9.8), is caused by a flaw that allows unauthorized access due to improper handling in a part of the Apache HTTP Server.
The vulnerability lets attackers manipulate URLs to bypass directory restrictions and access protected file system paths. SonicWall warns that this flaw could be exploited to hijack user sessions in certain situations.

“SonicWall and trusted security partners identified an additional exploitation technique using CVE-2024-38475, through which unauthorized access to certain files could enable session hijacking,” SonicWall said in the advisory. “SMA100 devices updated with firmware version 10.2.1.14-75sv are not vulnerable to CVE-2024-38475 or the related session hijacking technique.”

Impacted Versions:

SMA 100 Series (Models: 200, 210, 400, 410, 500v) running firmware 10.2.1.13-72sv and earlier

Fixed Version:

Firmware 10.2.1.14-75sv and above

SonicWall urges all customers using SMA 100 series devices to:

Update to the latest firmware to address vulnerabilities. Check admin login activity for unauthorized access. Monitor system logs and traffic for unusual behavior.

Check Also

Pwn2Own Berlin

Pwn2Own Berlin reveals 29 critical vulns in major tech firms

Pwn2Own Berlin 2025, a top cybersecurity contest, awarded $1,078,750 to researchers who discovered 29 zero-day …

Leave a Reply

Your email address will not be published. Required fields are marked *