peter bassill · operator
$ cve CVE-2023-44221 JSON

CVE-2023-44221 KEV

7.2
HIGH · CVSS 3.1 · EPSS 76.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-05-22.

Description

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS76.25% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2025-05-22
Public exploitnone known
Published2023-12-05
Last modified2026-06-17

CISA KEV

NameSonicWall SMA100 Appliances OS Command Injection Vulnerability
Added2025-05-01
Due2025-05-22
Vendor / productSonicWall / SMA100 Appliances
Ransomware usenone reported

Affected (10)

VendorProduct
sonicwallsma 200
sonicwallsma 200 firmware
sonicwallsma 210
sonicwallsma 210 firmware
sonicwallsma 400
sonicwallsma 400 firmware
sonicwallsma 410
sonicwallsma 410 firmware
sonicwallsma 500v
sonicwallsma 500v firmware

References

→ the Explorer  ·  watch your stack  ·  NVD