Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

One corner that generates revenue in the energy market is well maintained

Police say two students turned themselves back after a fatal stab wound outside a California high school

The documentary sheds light on Biden’s reaction to the murder of Shireen Abuakure | News in the Occupy West Bank

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » SONICWALL Patch 3 flaws in SMA 100 devices allow attackers to execute code as root
Identity

SONICWALL Patch 3 flaws in SMA 100 devices allow attackers to execute code as root

userBy userMay 8, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 8, 2025Ravi LakshmananNetwork Security/Vulnerabilities

Sonic Wall

SonicWall has released a patch that addresses three security flaws that affect SMA 100 Secure Mobile Access (SMA) appliances.

The vulnerabilities are listed below –

CVE-2025-32819 (CVSS Score: 8.8) – A vulnerability in SMA100 allows a remote authentication attacker with SSL-VPN user privileges to bypass the path traversal check, delete any file, and restart to factory default settings. CVE-2025-32820 (CVSS Score: 8.3) – A vulnerability in SMA100 allows a remote authentication attacker with privileged SSL-VPN users to insert a path traversal sequence to create any directory on the SMA appliance. SSL-VPN admin privileges can be used to insert shell command arguments to upload files to the appliance

“Attackers who have access to SMA SSL-VPN user accounts can chain these vulnerabilities to create sensitive system directories, raise privileges to SMA administrators, and write executables to the system directory,” Rapid7 said in the report. “This chain will execute root-level remote code.”

Cybersecurity

CVE-2025-32819 has been rated as a patch bypass for previously identified defects reported by the NCC group in December 2021.

The cybersecurity company noted that CVE-2025-32819 could have been misused in the wild as a zero day based on known indicators of compromise (IOCs) and incident response investigations. It is worth noting, however, that Sonic Wall does not mention the flaws that are weaponized in actual attacks.

The drawbacks affecting SMA 100 series, including SMA 200, 210, 400, 410, and 500V, are addressed in version 10.2.1.15-81SV.

This development is due to the aggressive exploitation of multiple security flaws in SMA 100 series devices in recent weeks, including CVE-2021-20035, CVE-2023-44221, and CVE-2024-38475. Users are advised to update their instances to the latest version for optimal protection.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleQilin ransomware ranked best in April 2025 with over 45 data leak disclosures
Next Article Coinbase wins DeRibit for $2.9 billion and earns a major push to crypto derivatives
user
  • Website

Related Posts

Over 38,000 Freedrain subdomains have been discovered after exploiting SEO to steal crypto wallet seed phrases

May 8, 2025

Qilin ransomware ranked best in April 2025 with over 45 data leak disclosures

May 8, 2025

Security tools alone won’t protect you – the control effect

May 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

One corner that generates revenue in the energy market is well maintained

Police say two students turned themselves back after a fatal stab wound outside a California high school

The documentary sheds light on Biden’s reaction to the murder of Shireen Abuakure | News in the Occupy West Bank

Key Takeout: Documentary name is Al Jazeera’s Abuakure Murderer | Crime News

Trending Posts

The documentary sheds light on Biden’s reaction to the murder of Shireen Abuakure | News in the Occupy West Bank

May 8, 2025

Key Takeout: Documentary name is Al Jazeera’s Abuakure Murderer | Crime News

May 8, 2025

US-UK Trade Contract: How is Trump’s global tariff talks formed? | International Trade News

May 8, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Health Technology Startup Kouper emerges from $10 million stealth in funding to transform the patient care transition

Did Figma kill Webflow and Framer with the release of the Figma site?

Metaworld Congress 2025: Madrid Takes Center Stage in Digital Innovation

Coinbase wins DeRibit for $2.9 billion and earns a major push to crypto derivatives

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.