Record summary

CVE-2023-44221 has a selected CVSS score of 7.2 (high). CISA lists CVE-2023-44221 in KEV.

Description

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · May 1, 2025 · CISA
VulnCheck KEV
Listed · Apr 29, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 2, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List10.2.1.9-57sv and earlier versionsaffected
CISAVersion data not supplied

References

3