SonicWall customers confront resurgence of actively exploited vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20035 | Authenticated OS Command Injection in SonicWall SMA100 Appliances CVE-2021-20035 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the management interface of SonicWall SMA100 series appliances. A remote attacker who has authenticated with low-level privileges can inject arbitrary operating system commands, which are executed on the appliance as the 'nobody' user. Per the CVSS scoring, the primary impact is on availability, potentially leading to denial of service, though command execution on the appliance could facilitate further abuse. The flaw affects SMA 200, 210, 400, 410, and 500v firmware. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-16, and related reporting describes ongoing attacks against SonicWall SMA 100 devices — including by threat group UNC6148 deploying the OVERSTEP rootkit and tailored backdoor malware, some against fully patched appliances — so defenders should treat this as actively exploited. Do: Patch to the fixed firmware release specified in the SonicWall advisory for your SMA model as soon as possible; federal agencies must follow the BOD 22-01 mitigation deadline per the CISA KEV required action. Restrict the management interface to trusted networks, enforce MFA on the portal, and hunt for signs of compromise such as the OVERSTEP rootkit, unexpected persistence, or unfamiliar accounts, since reporting indicates tailored backdoor malware in recent SMA 100 attacks. | 6.5 | 4% | KEV |
| large≈ tens of thousands of internet-exposed SMA 100-series appliances (order of magnitude 10k–100k) | |
| CVE-2023-44221 | OS Command Injection in SonicWall SMA100 SSL-VPN Management Interface SonicWall SMA100 appliances contain an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the SSL-VPN management interface. A remote attacker who is already authenticated with administrative privileges can submit crafted input containing special characters, causing arbitrary operating system commands to be executed on the appliance. Injected commands run as the low-privilege 'nobody' user, which limits immediate access but still yields high-impact confidentiality, integrity, and availability outcomes (CVSS 7.2) and can provide a foothold for further compromise. Affected products are the SMA 200, SMA 210, SMA 400, and SMA 410 appliance firmware and the SMA 500v virtual appliance firmware. The flaw carries a high EPSS score (75.1%, 99th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01, and reporting indicates both SonicWall and CISA have confirmed active in-the-wild exploitation of this and related SMA100 flaws. Do: Upgrade affected SMA100 appliances (SMA 200/210/400/410 and SMA 500v) to the latest vendor-patched firmware per SonicWall's advisory, as required under CISA KEV/BOD 22-01 timelines. Until patched, restrict access to the SSL-VPN management interface to trusted networks and enforce MFA on administrative accounts, since exploitation requires an authenticated administrative session. Given confirmed in-the-wild exploitation, review appliance logs for unauthorized administrative activity or command execution and rotate credentials if compromise is suspected. | 7.2 | 76% | KEV |
| large≈tens of thousands of internet-exposed SMA100 SSL-VPN appliances (order 10k–100k) | |
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) | |
| CVE-2024-3400 | Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent. Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled | |
| CVE-2024-53704 | Authentication Bypass in SonicWall SonicOS SSLVPN CVE-2024-53704 is a critical (CVSS 9.8) improper authentication flaw (CWE-287) in the SSLVPN authentication mechanism of SonicWall's SonicOS. A remote, unauthenticated attacker can exploit it over the network without user interaction, bypassing SSLVPN authentication to gain unauthorized access to the VPN and a foothold into protected internal networks. CISA notes known ransomware use, making this a high-value entry point for follow-on attacks. Any organization running SonicWall SonicOS with SSLVPN enabled is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-18, public scans show 5,000+ internet-exposed SonicWall firewalls still unpatched, and EPSS rates the 30-day exploitation probability at 95.1%. Do: Upgrade affected SonicOS deployments to the patched releases listed in SonicWall's advisory, prioritizing internet-facing SSLVPN endpoints. Until patched, restrict or disable SSLVPN exposure where feasible and hunt for signs of exploitation, since ransomware use is known. Remediation must satisfy CISA KEV required actions (apply vendor mitigations or discontinue use). | 9.8 | 95% | KEV ransomware |
| largeestimated tens of thousands of SSLVPN-enabled SonicWall firewall deployments, with at least ~5,000 confirmed still exposed and unpatched on the public internet | |
| CVE-2025-23006 | Unauthenticated Deserialization RCE in SonicWall SMA1000 Appliances CVE-2025-23006 is a deserialization of untrusted data flaw (CWE-502) in the Appliance Management Console (AMC) and Central Management Console (CMC) of SonicWall SMA1000 secure-access appliances. A remote, unauthenticated attacker who can reach a vulnerable console can submit crafted serialized data that, when processed, executes arbitrary operating-system commands on the appliance. Successful exploitation yields OS-level command execution, which is enough to fully compromise the appliance, pivot into the networks it protects, or stage ransomware. Any organization running a SonicWall SMA1000 appliance whose AMC or CMC is reachable — including management consoles exposed to the internet or to shared management networks — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-01-24 with known ransomware use, and EPSS assigns a 23.4% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known and a CVSS score has not yet been published. Do: Apply SonicWall's fix or vendor-specified mitigations immediately, per CISA's KEV required action; the available data does not state fixed version numbers, so use SonicWall's advisory to identify the correct firmware. Until patched, restrict AMC/CMC access to trusted management networks and remove any direct internet exposure of the consoles. Because ransomware use is known, hunt for indicators of compromise on internet-reachable SMA1000 appliances, including unexpected processes, new accounts, and unusual outbound connections. | 9.8 | 23% | KEV ransomware |
| largeon the order of tens of thousands of SMA1000-series appliance deployments, with likely thousands of management consoles internet-exposed | |
| CVE-2025-32819 | A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file po A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. NVD description · AI analysis pending | 8.8 group max | 6% | PoC |
| — |
Full article1,470 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The network security device vendor is making a regular appearance on CISA’s known exploited vulnerabilities catalog. Unlike its competitors, SonicWall hasn’t signed the secure-by-design pledge.
Listen to this article
0:00
Learn more.
Vulnerabilities are proliferating in SonicWall devices and software this year, putting the vendor’s customers at risk of intrusion via secure access gateways and firewalls.
The year started off on a sour note for the California-based company when it released security advisories for nine vulnerabilities on Jan. 7. The total number of vulnerabilities publicly disclosed by the company so far in 2025 has grown to 20.
SonicWall vulnerabilities are also making a consistent appearance on the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities (KEV) catalog. Cyber authorities confirm that attackers exploited four vulnerabilities in SonicWall products so far this year, and 14 total since late 2021.
Eight of those vulnerabilities have been exploited in ransomware campaigns, according to CISA.
SonicWall customers enjoyed a relative lull, with no new vulnerabilities exploited in the wild between March 2022 and September 2024, but malicious activity targeting the vendor’s equipment and software resurged earlier this year.
The four actively exploited vulnerabilities added to CISA’s catalog this year include a trio in SonicWall Secure Mobile Access (SMA) 100 Appliances: a pair of operating system command injection vulnerabilities, CVE-2023-44221 and CVE-2021-20035, and a critical deserialization of untrusted data vulnerability, CVE-2025-23006.
The other vulnerability recently exploited in the wild, CVE-2024-53704, is an improper authentication defect in the secure sockets layer virtual private network (SSL/VPN) mechanism in SonicWall SonicOS, the operating system that powers the company’s latest firewalls.
Three new SonicWall defects emerge
Earlier this week, the company disclosed and released patches for three new vulnerabilities — CVE-2025-32819, CVE-2025-32820 and CVE-2025-32821 — affecting SonicWall SMA 100 appliances.
Ryan Emmons, security researcher at Rapid7, discovered the new vulnerabilities last month and shared details with SonicWall on May 2. SonicWall’s security team acknowledged the disclosure in about 30 minutes and three days later shared a patch with Rapid7, which it validated as effective, Emmons said in a blog post.
SonicWall released a software update and published a security advisory for the vulnerabilities on Wednesday, five days after Rapid7 initially shared its findings with the company. For some SonicWall SMA 100 customers, it might have been too late.
“Rapid7 believes that CVE-2025-32819 may have been exploited in the wild, based on internal investigations and known private indicators of compromise,” Emmons told CyberScoop via email. “We haven’t yet observed any signs that CVE-2025-32820 and CVE-2025-32821 are exploited in the wild. However, SMA 100 series appliances are popular, so it’s likely that will change in the future.”
Attackers can exploit the three software defects and chain them together to achieve “remote code execution as root on a SonicWall SMA 100 appliance, which is the highest level of privileges and control an attacker can establish on a device like that,” Emmons said.
An attacker doesn’t need exceptional skills to reach that malicious goal. Cybercriminals can exploit CVE-2025-32819 once they gain access to any low-privilege user account on a vulnerable SonicWall SMA100, according to Emmons.
“That allows the attacker to delete a key file and reboot the SMA with a default administrator username and password,” Emmons said. “From there, they can use login and use the other two exploits to establish full control of the device.”
Matt Neiderman, chief strategy officer at SonicWall, told CyberScoop the company is unaware of any active exploitation of the three recently disclosed vulnerabilities — CVE-2025-32819, CVE-2025-32820 and CVE-2025-32821 — and SonicWall is working with Rapid7 to investigate further.
“While Rapid7 has published technical details and proof-of-concept exploits — currently we have no data to substantiate exploitation by malicious third parties — there is no indication from SonicWall that these specific vulnerabilities are being actively exploited in the wild,” Neiderman said.
“Given the availability of exploit code and the critical nature of these vulnerabilities, it’s strongly recommended to apply the latest patches provided by SonicWall to mitigate potential risks,” Neiderman added.
Security devices are under attack
SonicWall is among many network device vendors targeted by cybercriminals, and in every case it’s the customers who use vulnerable VPNs, firewalls and routers that are directly impacted.
One-third of all attacks in 2024 were linked to exploits, and the four most commonly exploited vulnerabilities were all contained in edge devices, Mandiant said in its M-Trends report released last month.
“Since these sorts of Linux-based appliances have restricted operating systems, they virtually never have endpoint protection and response or strong logging capabilities set up, so they make a great alcove for attackers to operate from within the network,” Emmons said.
Customers of larger network device vendors such as Palo Alto Networks, Cisco and Fortinet have been impacted by multiple exploited vulnerabilities in their products since 2024. A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks’ PAN-OS, CVE-2024-3400, was the most frequently exploited defect across all of Mandiant’s incident response engagements last year.
A pair of defects affecting Ivanti Connect Secure VPN and Ivanti Policy Secure appliances — CVE-2023-46805 and CVE-2024-21887 — were the next most frequently exploited vulnerabilities in 2024, according to Mandiant.
Ivanti appears in CISA’s KEV catalog more than any other firewall, VPN or router vendor over the past 17 months. Attackers have exploited five vulnerabilities in Ivanti products so far this year, and 16 total since the beginning of 2024.
Neiderman, as executives at other security device vendors have noted, said most of the SonicWall vulnerabilities exploited by attackers this year affect older technology. “These vulnerabilities relate primarily to legacy VPN appliances or SSL/VPN, which have been targeted by threat actors across most vendors in the industry,” he said.
“The rise in actively exploited vulnerabilities across the cybersecurity landscape this year also reflects a broader industry challenge,” Neiderman said. “We believe the increase in activity is a combination of the SMA (VPN) appliances being targeted by threat actors because VPN appliances for many vendors have been in the news as being vulnerable.”
Will vulnerabilities push SonicWall to secure-by-design?
Yet, there’s one piece missing from SonicWall’s commitment to bolster the security of its products. The company hasn’t signed CISA’s secure-by-design pledge, which the federal agency unveiled last year to publicly spur vendors to accept more responsibility for the security of their products.
More than 300 companies, including almost every major network device vendor — Palo Alto Networks, Cisco, Fortinet, Ivanti, Barracuda, Citrix and Check Point Software Technologies, among them — have signed the pledge.
The voluntary public commitment puts the onus on vendors to include well-established security features into their technology by default. This includes multifactor authentication, a reduction of default passwords and entire classes of vulnerabilities that can be prevented at scale, and efforts to increase the installation of security updates by customers.
“SonicWall has implemented all of the core principles defined in the secure-by-design pledge, and fully supports its objectives and formally kicked off the process,” Neiderman said.
The company’s latest gateway security appliances include security features by default, according to Neiderman. SonicWall announced an end-of-life for legacy SMA 100 series VPN appliances last year, and it recently rolled out a managed protection security suite as a default firewall license and service to ensure proper configuration and best practices, he added.
“Unmanaged and unpatched appliances are a liability,” Neiderman said. “Managed firewalls reduce the risk of breaches from newly discovered vulnerabilities.”
Neiderman said SonicWall intends to formally sign the pledge, but he did not say when or explain why it hasn’t already.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/sonicwall-exploited-vulnerabilities-surge/