Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    You can save up to $ 700 at my favorite bluety power stations for Labor Day

    August 30, 2025

    My favorite affordable phone cases are bogo free (new Google Pixel 10 series)

    August 30, 2025

    Vintage Electronics: Secure with a retarded tester

    August 30, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»SMA100 VPN weaknesses now exploited attacks
    Security

    SMA100 VPN weaknesses now exploited attacks

    PineapplesUpdateBy PineapplesUpdateApril 30, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    SMA100 VPN weaknesses now exploited attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SMA100 VPN weaknesses now exploited attacks

    Cyber ​​security company Sonicwall has warned customers that many weaknesses affecting its safe mobile access (SMA) equipment are now being actively exploited in attacks.

    On Tuesday, Sonicwall updated security advice Cve-2023-44221 And Cve-2024-38475 Security is to tag the two weaknesses as “potentially being exploited in the wild”.

    The CVE-2023-44221 is described as the SSL-VPN management interface described as the high-severity command injection vulnerability due to the inappropriate neutrality of special elements that enable the attackers to inject the arbitrary command as a “no” user.

    Second has been rated as a significant severity defect due to avoiding the output in the mod_rewrite, the second security bug, CVE-2024-38475, Apache HTTP Server 2.4.59 and before and before. Successful exploitation may allow informal, remote attackers to obtain code execution to obtain code execution by maping the URL at system locations allowed to serve by the successful exploitation server.

    Two weaknesses affect SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500V devices and the firmware versions are 10.2.1.1.14-75SV and are patched later.

    “During further analysis, Sonicwall and reliable security partners identified an additional exploitation technique using CVE-2024-38475, through which unauthorized access sessions to certain files can enable kidnapping,” Sonicwall warns In an updated advisor.

    “During further analysis, Sonicwall and Trusted Safety Partners identified that ‘CVE-2013-44221- Post Authentication OS Command Injection’ Gully is probably being exploited in the wild,” This added“Sonicwall Psirt recommends reviewing your SMA devices to ensure any unauthorized login.”

    Earlier this month, the company flagged off another high-seriousness defect about four years ago. Cve-2021-20035 As the Sma100 VPN devices have been actively exploited in distance code execution attacks targeting devices. A day later, Cyber ​​Security Company Arctic Wolf stated that CVE-2021–20035 was under active exploitation since at least January 2025.

    Sisa too Safety bugs added For Known exploitative weaknesses catalogOrder American federal agencies to secure their network against the ongoing attacks.

    In January, Sonicwall urged to patch a significant defect in the Sma1000 safe access gateway, which was being exploited in zero-day attacks, and a month later a month later a warning of an actively exploited disciplined bypass defect in the gene 6 and General 7 Firewalls allows hackers to allow VPN sessions.

    attacks exploited SMA100 VPN weaknesses
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFirst slate auto and now Isuju-Electric pick-up trucks can be the next Big EV battleground
    Next Article iPhone prices are rising, but not because you think
    PineapplesUpdate
    • Website

    Related Posts

    Security

    I invited Apple’s iPhone 17 event, and it took me under a rabbit hole of principles

    August 30, 2025
    Security

    Microsoft says that recently Windows update did not kill your SSD

    August 30, 2025
    Security

    Anthropic detects unavoidable: Jeanai-Keval attack, no human being

    August 30, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    You can save up to $ 700 at my favorite bluety power stations for Labor Day

    August 30, 2025

    My favorite affordable phone cases are bogo free (new Google Pixel 10 series)

    August 30, 2025

    Vintage Electronics: Secure with a retarded tester

    August 30, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.