• News/
  • https://www.bleepingcomputer.com/news/security/sonicwall-sma100-vpn-vulnerabilities-now-exploited-in-attacks/

SonicWall warns of more VPN flaws exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 30, 2025
·
Updated

Cybersecurity company SonicWall has warned customers that two older vulnerabilities impacting its Secure Mobile Access (SMA) appliances are now being actively exploited in attacks. On Tuesday, SonicWall updated security advisories for the CVE-2023-44221 and CVE-2024-38475 security flaws to tag the two vulnerabilities as "potentially being exploited in the wild." CVE-2023-44221 is described as a high-severity command injection vulnerability caused by improper neutralization of special elements in the SMA100 SSL-VPN management interface that enables attackers with admin privileges to inject arbitrary commands as a 'nobody' user. The second security bug, CVE-2024-38475, is rated as a critical severity flaw caused by improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier. Successful exploitation can allow unauthenticated, remote attackers to gain code execution by mapping URLs to file system locations permitted to be served by the server. The two vulnerabilities impact SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v devices and are patched in firmware version 10.2.1.14-75sv and later. "During further analysis, SonicWall and trusted security partners identified an additional exploitation technique using CVE-2024-38475, through which unauthorized access to certain files could enable session hijacking," SonicWall warned in an updated advisory. "During further analysis, SonicWall and trusted security partners identified that 'CVE-2023-44221 - Post Authe...

Read full article

Affected Software

6 affected components
SonicWall SMA 200 firmware
SonicWall SMA 210 Firmware
SonicWall SMA 400 firmware
SonicWall SMA 410
SonicWall SMA 500v Firmware
Apache Http Server=2.4.59

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the active exploitation of two vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances.

2

What vulnerabilities are being exploited in SonicWall SMA appliances?

The vulnerabilities mentioned are older flaws in SonicWall's Secure Mobile Access that have recently been reported as actively exploited.

3

Which SonicWall products are affected by these vulnerabilities?

The affected SonicWall products include SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v appliances.

4

What action is SonicWall advising customers to take regarding these vulnerabilities?

SonicWall recommends that customers update their firmware to mitigate the risks associated with these vulnerabilities.

5

What is the significance of timely updates for SonicWall users?

Timely updates are crucial for SonicWall users to protect against potential attacks leveraging these exploited vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203