VORANT. Threat Intelligence Sign in Get the full feed

SonicWall SMA100 flaw enables admin takeover

high vulnerability

A critical file-deletion vulnerability in SonicWall SMA100 appliances can let remote attackers gain administrator privileges; patch immediately.

The Information-technology Promotion Agency, Japan (IPA) issued an advisory regarding a vulnerability in SonicWall's SMA100 series, a line of remote-access appliances. The flaw allows a remote, unauthenticated attacker to delete arbitrary files on the device, which can ultimately be leveraged to obtain administrator-level privileges over the appliance.

SonicWall has assigned the issue a CVSSv3.0 score of 9.1, reflecting the severity of potential impact should the vulnerability be exploited. IPA notes that the vendor has stated this is a high-impact vulnerability and urges affected organizations to apply the available patched versions as soon as possible. End-of-life product lines will not receive a security patch, and IPA advises administrators to confirm patch availability and applicability directly with SonicWall.

No evidence of active exploitation is cited in the advisory, and no specific threat actors, malware, or campaigns are associated with this vulnerability at the time of publication. The advisory is primarily a call to action for organizations running SMA100 appliances to update to vendor-supplied fixed versions promptly.

Mentioned in this report

Vulnerabilities CVE-2021-20038KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/alert20211001.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free