CVE-2023-44221 is an OS Command Injection vulnerability affecting SonicWall SMA 200, 210, 400, 410, and 500v series SSL-VPN appliances. It allows a remote, authenticated administrator to inject arbitrary commands as a 'nobody' user due to improper neutralization of special elements. This vulnerability carries a CVSS score of 7.2 (High), indicating a low attack complexity and high impact on confidentiality, integrity, and availability. Notably, this CVE is actively exploited in the wild, as confirmed by its presence on the KEV catalog and extensive media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB. The high EPSS score and significant community discussion further underscore its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.2.1.9-57svCPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:* | ||
<= 10.2.1.9-57svCPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:* | ||
<= 10.2.1.9-57svCPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:* | ||
<= 10.2.1.9-57svCPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:* | ||
<= 10.2.1.9-57svCPE matchmatch criteria | cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.