CVE-2023-44221
SonicWall SMA100 Appliances OS Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 May 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 75.10% probability · 99th percentile
- CISA KEV
- Listed 1 May 2025 · due 22 May 2025
- Weakness
- CWE-78
- Affected
- sonicwall/sma 200 firmware · sonicwall/sma 210 firmware · sonicwall/sma 400 firmware · sonicwall/sma 410 firmware · sonicwall/sma 500v firmware
- Source
- PSIRT@sonicwall.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 ; https://nvd.nist.gov/vuln/detail/CVE-2023-44221
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.