nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-44221 CVE-2023-44221
HIGHCISA KEV
SonicWall SMA100 Appliances OS Command Injection Vulnerability
Record summary
CVE-2023-44221 has a selected CVSS score of 7.2 (high). CISA lists CVE-2023-44221 in KEV.
Description
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · May 1, 2025 · CISA
- VulnCheck KEV
- Listed · Apr 29, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 2, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 10.2.1.9-57sv and earlier versions | affected |
SMA100 AppliancesBrowse SonicWall / SMA100 Appliances | CISA | Version data not supplied | |
References
3psirt.global.sonicwall.comVendor advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44221