CVE-2023-44221
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
| CWE | CWE-78 |
| Vendor | sonicwall |
| Product | sma100 |
| Published | Dec 5, 2023 |
| Last Updated | Oct 21, 2025 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for sonicwall sma100
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-44221.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SonicWall / SMA100
10.2.1.9-57sv and earlier versions