Researchers detailed an attack chain dubbed SonicBoom affecting SonicWall SMA appliances, showing how attackers could move from stolen authentication tokens to remote shell access. The write-up ties the chain to CVE-2023-44221 and CVE-2024-38475, describing a path in which compromised session material can be leveraged to gain deeper access to the appliance.
The reports indicate the vulnerabilities can be combined to turn an initial foothold based on token theft into full command execution on affected SMA systems. The disclosure highlights the risk to organizations using SonicWall Secure Mobile Access appliances, where exposed or previously compromised tokens could enable attackers to escalate privileges and obtain a shell on the device.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
A security write-up titled "SonicBoom, From Stolen Tokens to Remote Shells" described an attack path affecting SonicWall SMA involving CVE-2023-44221 and CVE-2024-38475, connecting stolen tokens to remote shell access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
labs.watchtowr.com
Open sourcesummoning.team
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.