Vulnerability record · CVE-2023-44221 · published 5 December 2023
CVE-2023-44221: SonicWall SMA100 SSL-VPN management interface OS command injection
Sonicwall · Sma 200 Firmware
The SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds administrative privileges can execute arbitrary commands on the appliance as the 'nobody' user. Because the affected devices are internet-facing VPN gateways, compromise can expose the management plane and the network behind it.
Description
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives authenticated administrators OS command execution on an internet-facing VPN gateway, is in CISA KEV, and has a very high EPSS probability, though it requires high privileges to exploit.
What it is
The SMA100 SSL-VPN management interface fails to neutralize special elements, allowing command injection. A remote attacker who already holds administrative privileges can execute arbitrary commands on the appliance as the 'nobody' user. Because the affected devices are internet-facing VPN gateways, compromise can expose the management plane and the network behind it.
Impact
An authenticated administrator gains arbitrary OS command execution as the low-privileged 'nobody' user, which can be used to read data, pivot, or further compromise the appliance. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through the SMA100 SSL-VPN management interface (AV:N, AC:L). It requires high privileges (PR:H) and no user interaction (UI:N), so the attacker must already be an authenticated administrative user.
Exploitation
It is listed in CISA KEV (added 2025-05-01, due 2025-05-22) and has a very high EPSS 30-day probability of 0.7625 (99.5th percentile), indicating active exploitation is expected or observed. No ransomware campaign use is recorded.
What to do
- Apply the vendor fix per SonicWall PSIRT advisory SNWLID-2023-0018, or discontinue use if no mitigation is available, as directed by CISA KEV.
- Restrict management interface access to trusted administrative networks and never expose it directly to the internet.
- Enforce least privilege and strong authentication for SMA100 administrative accounts; audit and remove unused admin accounts.
- Monitor the appliance for unexpected processes or commands running as 'nobody' and review configuration changes.
- Follow BOD 22-01 guidance for cloud services where applicable.
Detection
- Alert on unexpected command execution or child processes spawned by the SSL-VPN management interface, especially under the 'nobody' user.
- Monitor SMA100 logs for anomalous administrative logins and management-interface requests containing shell metacharacters.
- Hunt for outbound connections or file changes on SMA100 appliances that do not match normal administrative activity.
- Correlate KEV/EPSS-driven vulnerability scans against internet-facing SMA100 management interfaces.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-44221 to the Known Exploited Vulnerabilities catalog on 1 May 2025 as "SonicWall SMA100 Appliances OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 22 May 2025.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44221 | US Government Resource |
Track CVE-2023-44221 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-44221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.