Known Exploited Vulnerability
7.2
HIGH
CVE-2023-44221
SonicWall SMA100 Appliances OS Command Injection V - [Actively Exploited]
Description

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

INFO

Published Date :

Dec. 5, 2023, 9:15 p.m.

Last Modified :

May 2, 2025, 2:15 p.m.

Remotely Exploitable :

Yes !

Impact Score :

5.9

Exploitability Score :

1.2
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

Required Action :

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes :

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 ; https://nvd.nist.gov/vuln/detail/CVE-2023-44221

Public PoC/Exploit Available at Github

CVE-2023-44221 has a 4 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2023-44221 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Sonicwall sma_210_firmware
2 Sonicwall sma_410_firmware
3 Sonicwall sma_500v_firmware
4 Sonicwall sma_200_firmware
5 Sonicwall sma_400_firmware
6 Sonicwall sma100_firmware
7 Sonicwall sma_210
8 Sonicwall sma_410
9 Sonicwall sma_500v
10 Sonicwall sma_200
11 Sonicwall sma_400
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2023-44221.

URL Resource
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 Vendor Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 Vendor Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

This Python script is tool that scrapes detailed information about one or more specified CVEs (Common Vulnerabilities and Exposures) from the cvedetails.com website and outputs the data in JSON format.

Python

Updated: 3 weeks, 5 days ago
0 stars 0 fork 0 watcher
Born at : May 5, 2025, 4:37 a.m. This repo has been linked 6 different CVEs too.

None

Python

Updated: 3 weeks, 2 days ago
12 stars 2 fork 2 watcher
Born at : May 1, 2025, 9:02 p.m. This repo has been linked 2 different CVEs too.

CISA Bot is a GitHub bot that automatically monitors the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog. When new vulnerabilities are published in the KEV, the bot creates GitHub issues in this repository with detailed information about each vulnerability.

Python

Updated: 6 hours, 44 minutes ago
1 stars 0 fork 0 watcher
Born at : Oct. 29, 2024, 10:19 a.m. This repo has been linked 151 different CVEs too.

EPSS & VEDAS Score Aggregator for CVEs

cve vulnerability exploit epss vedas

Updated: 3 weeks, 4 days ago
237 stars 34 fork 34 watcher
Born at : April 13, 2021, 4:50 a.m. This repo has been linked 137 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2023-44221 vulnerability anywhere in the article.

  • The Hacker News
SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Network Security / Vulnerability SonicWall has released patches to address three security flaws affecting SMA 100 Secure Mobile Access (SMA) appliances that could be fashioned to result in remote code ... Read more

Published Date: May 08, 2025 (3 weeks, 2 days ago)
  • Help Net Security
Yet another SonicWall SMA100 vulnerability exploited in the wild (CVE-2025-32819)

SonicWall has fixed multiple vulnerabilities affecting its SMA100 Series devices, one of which (CVE-2025-32819) appears to be a patch bypass for an arbitrary file delete vulnerability that was exploit ... Read more

Published Date: May 08, 2025 (3 weeks, 2 days ago)
  • BleepingComputer
SonicWall urges admins to patch VPN flaw exploited in attacks

SonicWall has urged its customers to patch three security vulnerabilities affecting its Secure Mobile Access (SMA) appliances, one of them tagged as exploited in attacks. Discovered and reported by Ra ... Read more

Published Date: May 08, 2025 (3 weeks, 2 days ago)
  • Dark Reading
CISA Warns 2 SonicWall Vulnerabilities Under Active Exploitation

Source: ktdesign via Alamy Stock PhotoNEWS BRIEFCISA added two older SonicWall bugs to the Known Exploited Vulnerabilities (KEV) catalog, marking the latest threat activity targeting the network secur ... Read more

Published Date: May 06, 2025 (3 weeks, 4 days ago)
  • Cyber Security News
New SonicBoom Attack Allows Bypass of Authentication for Admin Access

A critical new attack chain, dubbed “SonicBoom,” that enables remote attackers to bypass authentication and seize administrative control over enterprise appliances, including SonicWall Secure Mobile A ... Read more

Published Date: May 05, 2025 (3 weeks, 5 days ago)
  • Daily CyberSecurity
SonicWall Exploit Chain Exposes Admin Hijack Risk via CVE-2023-44221 and CVE-2024-38475

Image: watchTowr A newly exploit chain targeting SonicWall’s Secure Mobile Access (SMA) appliances has been released. Published by watchTowr Labs, the technical disclosure outlines how two distinct vu ... Read more

Published Date: May 05, 2025 (3 weeks, 5 days ago)
  • Help Net Security
Week in review: Critical SAP NetWeaver flaw exploited, RSAC 2025 Conference

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: RSAC 2025 Conference RSAC 2025 Conference took place at the Moscone Center in San Francisco. Check out ... Read more

Published Date: May 04, 2025 (3 weeks, 6 days ago)
  • Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
watchTowr Warns of Active Exploitation of SonicWall SMA 100 Devices

watchTowr reveals active exploitation of SonicWall SMA 100 vulnerabilities (CVE-2024-38475 & CVE-2023-44221) potentially leading to full system takeover and session hijacking. Learn about affected mod ... Read more

Published Date: May 03, 2025 (3 weeks, 6 days ago)
  • The Cyber Express
CISA Adds Two New Exploited Vulnerabilities to Its Catalog: CVE-2024-38475 and CVE-2023-44221

The Cybersecurity and Infrastructure Security Agency (CISA) recently updated its Known Exploited Vulnerabilities (KEV) Catalog, adding two vulnerabilities, CVE-2024-38475 and CVE-2023-44221, that are ... Read more

Published Date: May 02, 2025 (4 weeks, 1 day ago)
  • Help Net Security
Attackers exploited old flaws to breach SonicWall SMA appliances (CVE-2024-38475, CVE-2023-44221)

Attackers have been using two previously known vulnerabilities (CVE-2024-38475, CVE-2023-44221) to compromise SonicWall secure mobile access devices, the vendor has confirmed by updating the associate ... Read more

Published Date: May 02, 2025 (4 weeks, 1 day ago)
  • Cyber Security News
CISA Warns of SonicWall SMA100 OS Command Injection Vulnerability Exploited in Wild

CISA has added the SonicWall SMA100 OS Command Injection Vulnerability, tracked as CVE-2023-44221, to its Known Exploited Vulnerabilities (KEV) catalog. According to CISA’s May 1, 2025 advisory, this ... Read more

Published Date: May 02, 2025 (4 weeks, 1 day ago)
  • TheCyberThrone
CISA Adds Two Vulnerabilities to KEV Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities affecting Apache HTTP Server and SonicWall SMA100 appliances to its Known Exploited Vulnerabilities (KEV) ... Read more

Published Date: May 02, 2025 (4 weeks, 1 day ago)
  • security.nl
SonicWall SMA100 SSL-VPN's actief aangevallen via path traversal-lek

SonicWall SMA100 SSL-VPN's worden actief aangevallen via een kritiek path traversal-lek, alsmede een command injection-kwetsbaarheid, zo waarschuwt het bedrijf. Afgelopen december verscheen er een bev ... Read more

Published Date: May 01, 2025 (4 weeks, 2 days ago)
  • The Hacker News
SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance Models

Vulnerability / VPN Security SonicWall has revealed that two now-patched security flaws impacting its SMA100 Secure Mobile Access (SMA) appliances have been exploited in the wild. The vulnerabilities ... Read more

Published Date: May 01, 2025 (4 weeks, 2 days ago)
  • Cyber Security News
SonicWall OS Command Injection Vulnerability Exploited in the Wild

SonicWall has issued an urgent warning to customers that threat actors are actively exploiting a high-severity command injection vulnerability in its Secure Mobile Access (SMA) appliances. The vulnera ... Read more

Published Date: May 01, 2025 (4 weeks, 2 days ago)
  • Daily CyberSecurity
SonicWall Confirms Active Exploitation of SMA 100 Vulnerabilities – Urges Immediate Patching

On April 29, 2025, SonicWall issued an urgent update to two previously disclosed vulnerabilities affecting its SMA 100 Series appliances, confirming that both flaws are now actively being exploited in ... Read more

Published Date: May 01, 2025 (4 weeks, 2 days ago)
  • BleepingComputer
SonicWall: SMA100 VPN vulnerabilities now exploited in attacks

​Cybersecurity company SonicWall has warned customers that several vulnerabilities impacting its Secure Mobile Access (SMA) appliances are now being actively exploited in attacks. On Tuesday, SonicWal ... Read more

Published Date: Apr 30, 2025 (1 month ago)

The following table lists the changes that have been made to the CVE-2023-44221 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    May. 02, 2025

    Action Type Old Value New Value
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    May. 02, 2025

    Action Type Old Value New Value
    Added Date Added 2025-05-01
    Added Due Date 2025-05-22
    Added Required Action Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Added Vulnerability Name SonicWall SMA100 Appliances OS Command Injection Vulnerability
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Apr. 30, 2025

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • Initial Analysis by [email protected]

    Dec. 13, 2023

    Action Type Old Value New Value
    Added CVSS V3.1 NIST AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 No Types Assigned https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 Vendor Advisory
    Added CWE NIST CWE-78
    Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:* versions up to (including) 10.2.1.9-57sv OR cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:* versions up to (including) 10.2.1.9-57sv OR cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:* versions up to (including) 10.2.1.9-57sv OR cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:* versions up to (including) 10.2.1.9-57sv OR cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:* versions up to (including) 10.2.1.9-57sv OR cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
  • CVE Received by [email protected]

    Dec. 05, 2023

    Action Type Old Value New Value
    Added Description Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
    Added Reference SonicWALL, Inc. https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 [No types assigned]
    Added CWE SonicWALL, Inc. CWE-78
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2023-44221 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

46.25 }} 3.55%

score

0.97482

percentile

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
© cvefeed.io
Latest DB Update: May. 31, 2025 15:14