๐Ÿ” CVE Alert

CVE-2023-44221

HIGH 7.2 โš ๏ธ CISA KEV
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

CWE CWE-78
Vendor sonicwall
Product sma100
Published Dec 5, 2023
Last Updated Oct 21, 2025
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for sonicwall sma100

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-44221.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SonicWall / SMA100
10.2.1.9-57sv and earlier versions

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
psirt.global.sonicwall.com: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44221