The US Cybersecurity and Infrastructure Security Agency (CISA) has added an old SonicWall vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
Federal Civilian Executive Branch (FCEB) agencies have three weeks to install the patch or stop using the product entirely.
SonicWall updated its security advisory, upgrading the severity score of the flaw from medium to high.
The vulnerability allows a remote authenticated attacker to inject arbitrary commands, potentially leading to code execution.