← Vulnerability feed

Vulnerability record · CVE-2023-44221 · published 5 December 2023

CVE-2023-44221: SonicWall SMA100 SSL-VPN management interface OS command injection

Sonicwall · Sma 200 Firmware

The SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds administrative privileges can execute arbitrary commands on the appliance as the 'nobody' user. Because the affected devices are internet-facing VPN gateways, compromise can expose the management plane and the network behind it.

7.2 CVSS 3.1 High CISA KEV since 1 May 2025 EPSS 76% · top 0.5% CWE-78 · OS command injection
7.2CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw gives authenticated administrators OS command execution on an internet-facing VPN gateway, is in CISA KEV, and has a very high EPSS probability, though it requires high privileges to exploit.

What it is

The SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds administrative privileges can execute arbitrary commands on the appliance as the 'nobody' user. Because the affected devices are internet-facing VPN gateways, compromise can expose the management plane and the network behind it.

Impact

An authenticated administrator gains arbitrary OS command execution as the low-privileged 'nobody' user, which can be used to read data, pivot, or further compromise the appliance. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through the SMA100 SSL-VPN management interface (AV:N, AC:L). It requires high privileges (PR:H) and no user interaction (UI:N), so the attacker must already be an authenticated administrative user.

Exploitation

It is listed in CISA KEV (added 2025-05-01, due 2025-05-22) and has a very high EPSS 30-day probability of 0.7625 (99.5th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is recorded.

What to do

  • Apply the vendor fix per SonicWall PSIRT advisory SNWLID-2023-0018, or discontinue use if no mitigation is available, as directed by CISA KEV.
  • Restrict management interface access to trusted administrative networks and never expose it directly to the internet.
  • Enforce least privilege and strong authentication for SMA100 administrative accounts; audit and remove unused admin accounts.
  • Monitor the appliance for unexpected processes or commands running as 'nobody' and review configuration changes.
  • Follow BOD 22-01 guidance for cloud services where applicable.

Detection

  • Alert on unexpected command execution or child processes spawned by the SSL-VPN management interface, especially under the 'nobody' user.
  • Monitor SMA100 logs for anomalous administrative logins and management-interface requests containing shell metacharacters.
  • Hunt for outbound connections or file changes on SMA100 appliances that do not match normal administrative activity.
  • Correlate KEV/EPSS-driven vulnerability scans against internet-facing SMA100 management interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-44221 to the Known Exploited Vulnerabilities catalog on 1 May 2025 as "SonicWall SMA100 Appliances OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 May 2025.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-44221 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-20038SonicWall SMA 100 appliances stack buffer overflow in mod_cgiA stack-based buffer overflow in the Apache httpd mod_cgi module of SonicWall SMA 100 series appliances lets a remote unauthenticated attacker overwr…KEVEPSS 100%analysed9.8CVE-2021-20028SonicWall SRA appliances SQL injection in end-of-life firmwareSonicWall Secure Remote Access (SRA) appliances running all 8.x firmware and 9.0.0.9-26sv or earlier fail to neutralize SQL commands, allowing SQL in…KEVEPSS 30%analysed9.8CVE-2021-20016SonicWall SMA100 SSLVPN SQL injection allows unauthenticated accessSonicWall SSLVPN SMA100 firmware 10.x contains a SQL injection flaw in its SSLVPN interface. A remote attacker with no credentials can inject SQL to …KEVEPSS 40%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed6.5CVE-2021-20035SonicWall SMA100 management interface OS command injectionThe SMA100 management interface fails to neutralize special elements, letting a remote authenticated attacker inject arbitrary commands that run as t…KEVEPSS 4.2%analysed9.8CVE-2022-22273Sonicwall sma 200 firmware os command injection vulnerabilityImproper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…EPSS 1.9%9.8CVE-2021-20042Sonicwall sma 200 firmware vulnerabilityAn unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi…EPSS 2.6%9.8CVE-2021-20045Sonicwall sma 200 firmware classic buffer overflow vulnerabilityA buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execut…EPSS 25%

Source: NIST National Vulnerability Database (record CVE-2023-44221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.