CVE-2024-38475Disclosure(apache / http_server)

HIGHCVSS 9.1 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for apache http_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

6.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-22. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-116

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • http_server
  • ontap_9
  • sma_200
  • sma_200_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
http_serverontap_9sma_200sma_200_firmwaresma_210sma_210_firmwaresma_400sma_400_firmwaresma_410sma_410_firmware

1 version affected across 12 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-27: 1Active Exploitation · 2026-04-27: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-27: 104-1004-27
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-271
Active Exploitation1
Full discourse2 posts
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️ We are observing heightened activity against SonicWall SMA 100 appliances Multiple IPs have recently hit our honeypot fleet with paired CVE-2024-38475 reads Public PoCs demonstrate the exploit against benign paths, while these operators are reading temp.db and persist.db - session token and credential databases respectively. These two files, when read, could be used to chain into the post-auth command injection (CVE-2023-44221) for full pre-auth RCE. Given these are older vulns, the activity may also be recon ahead of exploitation using a more recent SMA vulnerability. IOCs and details on Defused Radar 👉 http://console.defusedcyber.com/radar

    Post summary

    The post reports heightened activity against SonicWall SMA 100, noting IPs that accessed CVE-2024‑38475 and read credential databases, potentially chaining into a pre‑auth RCE via CVE-2023‑44221, with public PoCs available but no specific exploit code described.

    0612335.8K
    7.4K followersView on X
  • BreakGlass Intelligence@BreakGlassIntel
    Disclosure

    http://cpuid.com runs Apache 2.4.59/66 — 34 known CVEs. CVE-2024-38475 (path traversal in mod_rewrite) is the probable initial access vector. CPUID downloads are clean now. Verified hashes in the full report.

    Post summary

    The post reports that cpuid.com is running an older Apache version with multiple CVEs, identifies CVE-2024-38475 path traversal as the likely initial access vector, and confirms that download files are clean with verified hashes.

    11000148
    611 followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appapachehttp_server---
Appnetappontap_9---
HWsonicwallsma_200---
OSsonicwallsma_200_firmware---
HWsonicwallsma_210---
OSsonicwallsma_210_firmware---
HWsonicwallsma_400---
OSsonicwallsma_400_firmware---
HWsonicwallsma_410---
OSsonicwallsma_410_firmware---
HWsonicwallsma_500v---
OSsonicwallsma_500v_firmware---

Explore more