ZeroHour
Dark Readingpublished ()ingested Alexander Culafi

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

highExploit / PoC exploited in the wildimportance 78
AI summary · glm-5.3-flash

New SonicWall SMA 1000 zero-days enable unauthenticated remote code execution, with exploitation observed following earlier summer attacks on other SonicWall edge zero-days.

Zero-day vulnerabilities in SonicWall's SMA 1000 secure access appliances allow unauthenticated remote code execution, and exploitation activity is being observed. This follows attacks earlier in the summer that abused two other zero-day vulnerabilities in SonicWall edge devices. Internet-facing appliances used for remote access make this an urgent patching priority for defenders.

  • Unauthenticated RCE zero-days affect SonicWall SMA 1000 series appliances
  • Exploitation follows earlier summer attacks on two other SonicWall edge zero-days
  • SMA appliances are internet-facing devices commonly used for remote access
VendorsSonicWall
ProductsSMA 1000
Full article

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at darkreading.com.