Skip to main content

CVE detail

CVE-2024-38475

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

CVSS 9.1 · CriticalBuzz score 67.2KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 67.2

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 27.7 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
27.7
15 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
15 source links · newest first
  • The software update includes additional file checks and helps users remove the known rootkit deployed in a recent campaign.

    newswww.securityweek.comSep 24, 2025, 8:28 AM
  • SonicWall has released new firmware for its Secure Mobile Access (SMA) 100 series appliances, adding file-checking capabilities that help users remove known rootkit malware. The malware in question is the OVERSTEP user-mode rootkit, deployed by threat group UNC6148. The campaign In July 2025, Mandiant incident responders and Google Threat Intelligence Group (GTIG) threat analysts warned about a SonicWall SMA exploitation campaign perpetrated by UNC6148. Attackers leveraged previously stolen local administrator credentials to establish an SSL … More →

    newswww.helpnetsecurity.comSep 23, 2025, 1:07 PM
  • SonicWall addressed a critical vulnerability, tracked as CVE-2025-40599 (CVSS score of 9.1), in SMA 100 appliances SonicWall addressed a critical vulnerability, tracked as CVE-2025-40599 (CVSS score of 9.1), in SMA 100 appliances. Experts warn customers to check their installs for Indicators of Compromise (IoCs) associated with Overstep malware attacks. The issue is an authenticated arbitrary […]

    newssecurityaffairs.comJul 24, 2025, 12:59 PM
  • SonicWall advises organizations to patch SMA 100 appliances and look for IoCs associated with Overstep malware attacks.

    newswww.securityweek.comJul 24, 2025, 10:18 AM
  • A group of hackers known for stealing enterprise data for extortion purposes has developed a persistent rootkit for SonicWall Secure Mobile Access (SMA) 100 series appliances. The rootkit was seen deployed on end-of-life but fully patched SMA 100 appliances with the help of administrative credentials likely obtained in past compromises. “GTIG assesses with high confidence […]

    newswww.csoonline.comJul 17, 2025, 9:46 PM
  • UNC6148 targets SonicWall devices with Overstep malware, using a backdoor and rootkit for data theft, extortion, or ransomware. Google’s Threat Intelligence Group warns that a threat actor tracked as UNC6148 has been targeting SonicWall SMA appliances with new malware dubbed Overstep. Active since at least October 2024, the group uses a backdoor and user-mode rootkit […]

    newssecurityaffairs.comJul 17, 2025, 7:47 AM
  • Unknown intruders are targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances and deploying a novel, persistent backdoor / rootkit, analysts with Google’s Threat Intelligence Group (GTIG) have warned. The analysts say UNC6148 – as they dubbed the threat group – is likely financially motivated. “An organization targeted by UNC6148 in May 2025 was posted to the ‘World Leaks’ data leak site (DLS) in June 2025, and UNC6148 activity overlaps with publicly … More →

    newswww.helpnetsecurity.comJul 16, 2025, 4:52 PM
  • A threat actor that may be financially motivated is targeting SonicWall devices with a backdoor and user-mode rootkit.

    newswww.securityweek.comJul 16, 2025, 2:00 PM
  • 5th May – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 5th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Three major UK retailers – Co-op, Harrods and Marks & Spencer (M&S) – were hit by cyberattacks that disrupted operations and compromised sensitive data. The attacks are believed linked to the Scattered […]

    vendorresearch.checkpoint.comMay 5, 2025, 11:42 AM
  • PoC code targeting two exploited SonicWall flaws was published just CISA added them to the KEV catalog.

    newswww.securityweek.comMay 5, 2025, 9:55 AM
  • Attackers have been using two previously known vulnerabilities (CVE-2024-38475, CVE-2023-44221) to compromise SonicWall secure mobile access devices, the vendor has confirmed by updating the associated advisories. CISA has added the two flaws to its Known Exploited Vulnerabilities catalog, and Watchtowr researchers have analyzed how they can be being chained together and have released a proof-of-concept exploit (or, as they call it, a “Detection Artefact Generator”). The exploited vulnerabilities (CVE-2024-38475, CVE-2023-44221) Sonicwall SMA100 appliances are VPN … More →

    newswww.helpnetsecurity.comMay 2, 2025, 1:16 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall SMA100 and Apache HTTP Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Qualitia Active! Mail, Broadcom Brocade Fabric OS, and Commvault Web Server flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: […]

    newssecurityaffairs.comMay 2, 2025, 7:49 AM
  • SonicWall has updated the advisories for two vulnerabilities to warn that they are being exploited in the wild.

    newswww.securityweek.comMay 1, 2025, 10:00 AM
  • SonicWall confirmed that threat actors actively exploited two vulnerabilities impacting its SMA100 Secure Mobile Access (SMA) appliances. SonicWall revealed that attackers actively exploited two security vulnerabilities, tracked as CVE-2023-44221 and CVE-2024-38475, in its SMA100 Secure Mobile Access appliances. Below are the descriptions of the two flaws: “During further analysis, SonicWall and trusted security partners identified an […]

    newssecurityaffairs.comMay 1, 2025, 8:31 AM
  • SonicWall has released patches for multiple high-severity flaws in the SMA100 SSL-VPN secure access gateway.

    newswww.securityweek.comDec 6, 2024, 12:26 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence