Junglewise Threat Intelligence

CVE-2023-44221: SonicWall SMA100 Appliances OS Command Injection Vulnerability

CVE-2023-44221 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2025-05-01

Technologies: SonicWall SMA100. Vendors: SonicWall.

Executive brief

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface. A remote, authenticated attacker with administrative privileges can inject arbitrary commands executed as the 'nobody' user.

Affected products

  • SonicWall SMA 200 firmware up to (including) 10.2.1.9-57sv
  • SonicWall SMA 210 firmware up to (including) 10.2.1.9-57sv
  • SonicWall SMA 400 firmware up to (including) 10.2.1.9-57sv
  • SonicWall SMA 410 firmware up to (including) 10.2.1.9-57sv
  • SonicWall SMA 500v firmware up to (including) 10.2.1.9-57sv

Timeline

  • 2023-12-05: disclosed: Initial NVD publication date
  • 2025-05-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-05-22: other: CISA KEV remediation due date

Related threats