
⚠️ We are observing heightened activity against SonicWall SMA 100 appliances Multiple IPs have recently hit our honeypot fleet with paired CVE-2024-38475 reads Public PoCs demonstrate the exploit against benign paths, while these operators are reading temp.db and persist.db - session token and credential databases respectively. These two files, when read, could be used to chain into the post-auth command injection (CVE-2023-44221) for full pre-auth RCE. Given these are older vulns, the activity may also be recon ahead of exploitation using a more recent SMA vulnerability. IOCs and details on Defused Radar 👉 http://console.defusedcyber.com/radar
Post summary
The post reports heightened activity against SonicWall SMA 100, noting IPs that accessed CVE-2024‑38475 and read credential databases, potentially chaining into a pre‑auth RCE via CVE-2023‑44221, with public PoCs available but no specific exploit code described.

