
⚠️ We are observing heightened activity against SonicWall SMA 100 appliances Multiple IPs have recently hit our honeypot fleet with paired CVE-2024-38475 reads Public PoCs demonstrate the exploit against benign paths, while these operators are reading temp.db and persist.db - session token and credential databases respectively. These two files, when read, could be used to chain into the post-auth command injection (CVE-2023-44221) for full pre-auth RCE. Given these are older vulns, the activity may also be recon ahead of exploitation using a more recent SMA vulnerability. IOCs and details on Defused Radar 👉 http://console.defusedcyber.com/radar
Post summary
Observations indicate increased exploitation attempts targeting SonicWall SMA 100 appliances via CVE‑2024‑38475, with attackers reading credential databases and potentially chaining to a pre‑auth RCE (CVE‑2023‑44221). Public PoCs exist, but no patches or mitigations are referenced.
