Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
References
| Link | Resource |
|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 | Vendor Advisory |
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44221 | US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
History
31 Oct 2025, 15:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44221 - US Government Resource |
21 Oct 2025, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 08:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 - Vendor Advisory |
13 Dec 2023, 15:33
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 - Vendor Advisory | |
| First Time |
Sonicwall sma 400
Sonicwall sma 200 Sonicwall sma 200 Firmware Sonicwall sma 410 Firmware Sonicwall Sonicwall sma 210 Firmware Sonicwall sma 410 Sonicwall sma 400 Firmware Sonicwall sma 500v Sonicwall sma 210 Sonicwall sma 500v Firmware |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| CPE | cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:* |
|
| CWE | CWE-78 |
05 Dec 2023, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-12-05 21:15
Updated : 2025-10-31 15:56
NVD link : CVE-2023-44221
Mitre link : CVE-2023-44221
CVE.ORG link : CVE-2023-44221
JSON object : View
Products Affected
sonicwall
- sma_400
- sma_200_firmware
- sma_400_firmware
- sma_210_firmware
- sma_200
- sma_210
- sma_410_firmware
- sma_500v
- sma_500v_firmware
- sma_410
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
