Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hybrid Li alloy tech beats solid-state battery energy density as Gangfeng starts mass cell production

    New Roborock Saros 20 robot vacuum appears ahead of launch

    OmegaLinux switches from Ubuntu to Arch in 2026.02.21 release

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026
    • Business

      Gartner: Why neoclouds are the future of GPU-as-a-Service

      February 21, 2026

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026
    • Crypto

      XRP Struggles as On-Chain Stress Mounts: Is a Bottom Forming?

      February 23, 2026

      Vitalik Buterin Sold Over 8,800 ETH in February: Did It Impact the Price?

      February 23, 2026

      Vitalik Buterin Explains How Crypto Can Protect Users When Perfect Security Remains Impossible

      February 23, 2026

      Ethereum, Solana Defy L1 Myth — Bitwise CIO Sees Prediction Markets Changing Everything

      February 23, 2026

      5 Critical Factors That Could End Gold’s 7-Month Green Streak

      February 23, 2026
    • Technology

      Hybrid Li alloy tech beats solid-state battery energy density as Gangfeng starts mass cell production

      February 23, 2026

      New Roborock Saros 20 robot vacuum appears ahead of launch

      February 23, 2026

      OmegaLinux switches from Ubuntu to Arch in 2026.02.21 release

      February 23, 2026

      Samsung Galaxy S26 Ultra stars in CPU and GPU hands-on benchmark tests ahead of official debut

      February 23, 2026

      Zero-click reality is rewriting the rules of search for brands

      February 23, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»CISA tags SonicWall VPN flaw as actively exploited in attacks
    Technology

    CISA tags SonicWall VPN flaw as actively exploited in attacks

    TechAiVerseBy TechAiVerseApril 17, 2025No Comments3 Mins Read4 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    CISA tags SonicWall VPN flaw as actively exploited in attacks
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    CISA tags SonicWall VPN flaw as actively exploited in attacks

    On Wednesday, CISA warned federal agencies to secure their SonicWall Secure Mobile Access (SMA) 100 series appliances against attacks exploiting a high-severity remote code execution vulnerability.

    Tracked as CVE-2021-20035, this security flaw impacts SMA 200, SMA 210, SMA 400, SMA 410, and SMA 500v (ESX, KVM, AWS, Azure) devices. Successful exploitation can allow remote threat actors with low privileges to execute arbitrary code in low-complexity attacks.

    “Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a ‘nobody’ user, which could potentially lead to code execution,” SonicWall explains in an advisory updated this week.

    SonicWall patched this vulnerability almost four years ago, in September 2021, when the company said it could only be exploited to take down vulnerable appliances in denial-of-service (DoS) attacks.

    However, on Monday, it updated the CVE-2021-20035 security advisory to flag it as exploited in attacks, upgrade the CVSS severity score from medium to high, and expand the impact to include code execution.

    “This vulnerability is believed to be actively exploited in the wild. As a precautionary measure, SonicWall PSIRT has updated the summary and revised the CVSS score to 7.2,” SonicWall said.

    Product Platform Impacted Version Fixed version
    SMA 100 Series • SMA 200
    • SMA 210
    • SMA 400
    • SMA 410
    • SMA 500v (ESX, KVM, AWS, Azure)
    10.2.1.0-17sv and earlier 10.2.1.1-19sv and higher
    10.2.0.7-34sv and earlier 10.2.0.8-37sv and higher
    9.0.0.10-28sv and earlier 9.0.0.11-31sv and higher

    Yesterday, CISA confirmed the vulnerability is now being abused in the wild by adding it to the Known Exploited Vulnerabilities catalog, which lists security flaws flagged by the cybersecurity agency as actively exploited in attacks.

    As mandated by the Binding Operational Directive (BOD) 22-01 issued in November 2021, Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until May 7th, to secure their networks against ongoing attacks.

    While BOD 22-01 only applies to U.S. federal agencies, all network defenders should prioritize patching this security vulnerability as soon as possible to block potential breach attempts.

    “These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned.

    In February, SonicWall also warned of an actively exploited authentication bypass flaw in Gen 6 and Gen 7 firewalls that could let hackers hijack VPN sessions.

    One month earlier, the company urged customers to patch a critical vulnerability affecting SMA1000 secure access gateways following reports that it had already been exploited in zero-day attacks.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleOver 16,000 Fortinet devices compromised with symlink backdoor
    Next Article New Windows Server emergency updates fix container launch issue
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Hybrid Li alloy tech beats solid-state battery energy density as Gangfeng starts mass cell production

    February 23, 2026

    New Roborock Saros 20 robot vacuum appears ahead of launch

    February 23, 2026

    OmegaLinux switches from Ubuntu to Arch in 2026.02.21 release

    February 23, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025691 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025278 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025159 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025120 Views
    Don't Miss
    Technology February 23, 2026

    Hybrid Li alloy tech beats solid-state battery energy density as Gangfeng starts mass cell production

    Hybrid Li alloy tech beats solid-state battery energy density as Gangfeng starts mass cell production…

    New Roborock Saros 20 robot vacuum appears ahead of launch

    OmegaLinux switches from Ubuntu to Arch in 2026.02.21 release

    Samsung Galaxy S26 Ultra stars in CPU and GPU hands-on benchmark tests ahead of official debut

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Hybrid Li alloy tech beats solid-state battery energy density as Gangfeng starts mass cell production

    February 23, 20261 Views

    New Roborock Saros 20 robot vacuum appears ahead of launch

    February 23, 20262 Views

    OmegaLinux switches from Ubuntu to Arch in 2026.02.21 release

    February 23, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.